logo

PIKABOT, I choose you!

ID: 7284a296-bb27-576b-90ba-88e374a863f2

STIX ID: report--7284a296-bb27-576b-90ba-88e374a863f2

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2024-02-24

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzed a newly observed PIKABOT campaign (Feb 8) and an updated PIKABOT loader/core that uses heavy obfuscation, novel unpacking from .data base64 chunks, direct syscalls to evade EDR, reflective PE loading, process hollowing into ctfmon.exe, RC4-based network communications, and runtime plaintext configuration. The report details anti-debugging approaches, collection/initial beacon behavior, supported commands (including injection and remote execution), YARA rules, and multiple IOCs (file hashes, domains, and IP:port C2 servers) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.