logo

Gotta Catch 'Em All: Detecting PikaBot Delivery Techniques · Blog · Sublime Security

ID: d54c0a3c-8d3e-514b-9eb0-f77b466a89de

STIX ID: report--d54c0a3c-8d3e-514b-9eb0-f77b466a89de

Feed Name: Sublime Security Blog

Threat Score
75/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

**PikaBot** is a modular backdoor/loader active since early 2023 that is distributed primarily via phishing email campaigns and multi-stage delivery (auto-downloaded ZIPs, PDFs with embedded URLs, Excel SMB links, ISO attachments). The malware features a loader and core component capable of injecting shellcode/DLLs/executables, employs evasion techniques (ADVobfuscator, anti-analysis, sleep via NtContinue, geolocation checks), leverages DLL search order hijacking and CVE-2023-33151 in deliveries, and commonly acts as a conduit for secondary payloads like infostealers or ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.