logo

PikaBot: a Guide to its Deep Secrets and Operations

ID: 30e53f43-3c91-5d9a-973f-ad948cff5aa6

STIX ID: report--30e53f43-3c91-5d9a-973f-ad948cff5aa6

Feed Name: Sekoia.com

Threat Score
78/100

Date Published: 2024-06-03

Date Updated: 2026-07-20

...
...

This report analyzes PikaBot (version 1.8.32-beta), a sophisticated multi-stage malware loader used by Initial Access Brokers (notably TA577) to distribute payloads (including Cobalt Strike and links to Black Basta ransomware). It details loader internals, anti-analysis and evasion techniques (string/PE obfuscation, junk code, RC4/base64 stage blobs, SysWhispers2 direct syscalls), C2 communication and infrastructure tracking (360+ C2 IPs, TLS/JARM heuristics), distribution methods (phishing, malvertising), YARA signatures, scripts for analysis, and a comprehensive IoC list for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.