PikaBot: a Guide to its Deep Secrets and Operations
ID: 30e53f43-3c91-5d9a-973f-ad948cff5aa6
STIX ID: report--30e53f43-3c91-5d9a-973f-ad948cff5aa6
Feed Name: Sekoia.com
This report analyzes PikaBot (version 1.8.32-beta), a sophisticated multi-stage malware loader used by Initial Access Brokers (notably TA577) to distribute payloads (including Cobalt Strike and links to Black Basta ransomware). It details loader internals, anti-analysis and evasion techniques (string/PE obfuscation, junk code, RC4/base64 stage blobs, SysWhispers2 direct syscalls), C2 communication and infrastructure tracking (360+ C2 IPs, TLS/JARM heuristics), distribution methods (phishing, malvertising), YARA signatures, scripts for analysis, and a comprehensive IoC list for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
