Pkybot

Aliases: Bublik, Pykbot, TBag

First seen
2013-01-01 00:00:00
Malware type
downloader, trojan
Family
Malware family
Last IoC activity
2026-07-21 04:37:57
Profile updated
2026-07-07 15:15:47

Targeted industries: financial-services

Context

Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Pkybot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Pkybot (report)
  • blog.kleissner.org (report)
  • webcache.googleusercontent.com — Search (report)

External references