PIKABOT, I choose you!
ID: 7284a296-bb27-576b-90ba-88e374a863f2
STIX ID: report--7284a296-bb27-576b-90ba-88e374a863f2
Feed Name: Elastic Security Labs
Elastic Security Labs analyzed a newly observed PIKABOT campaign (Feb 8) and an updated PIKABOT loader/core that uses heavy obfuscation, novel unpacking from .data base64 chunks, direct syscalls to evade EDR, reflective PE loading, process hollowing into ctfmon.exe, RC4-based network communications, and runtime plaintext configuration. The report details anti-debugging approaches, collection/initial beacon behavior, supported commands (including injection and remote execution), YARA rules, and multiple IOCs (file hashes, domains, and IP:port C2 servers) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
