logo

Distinctive Campaign Evolution of Pikabot Malware

ID: 52c3eb19-9a05-5042-af12-a327ddf8a7d4

STIX ID: report--52c3eb19-9a05-5042-af12-a327ddf8a7d4

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2024-04-02

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

**PikaBot backdoor campaigns and analysis**: This report from McAfee Labs details PikaBot, a modular loader/core backdoor that uses diverse distribution vectors (HTML, JavaScript, SMB moniker links, Excel with embedded links, JAR), performs code injection into legitimate processes, communicates with C2 over HTTPS on non-standard ports, and includes IOCs (file hashes and C2 IP:port pairs); McAfee notes active blocking of samples across the described campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.