Pkybot
Aliases: Bublik, Pykbot, TBag
- First seen
- 2013-01-01 00:00:00
- Malware type
- downloader, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:37:57
- Profile updated
- 2026-07-07 15:15:47
Targeted industries: financial-services
Context
Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Pkybot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Pkybot (report)
- blog.kleissner.org (report)
- webcache.googleusercontent.com — Search (report)