Pikabot Malware Surfaces as Qakbot Replacement for Black Basta Attacks
ID: 73a10f10-8fd8-5163-8e09-10b426272bb1
STIX ID: report--73a10f10-8fd8-5163-8e09-10b426272bb1
Feed Name: Dark Reading
Date Published: 2024-01-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers observed Water Curupira (linked to Black Basta ransomware activity) running widespread phishing campaigns that deliver a new loader named Pikabot — a Qakbot-like multi-stage loader that extracts a DLL payload, performs system reconnaissance and exfiltration, and drops Cobalt Strike beacons tied to Black Basta. The campaigns use thread-jacking and password-protected attachments (.ZIP/.IMG/.PDF with obfuscated JavaScript or LNK/DLL chains) to increase legitimacy; Pikabot avoids systems using Russian or Ukrainian language and communicates with numerous C2 domains. The report includes IoCs and standard email/phishing hygiene and patching/backups recommendations to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
