PikaBot: a Guide to its Deep Secrets and Operations
ID: e7665462-cf4b-5ec2-aae3-0b47457b7ccf
STIX ID: report--e7665462-cf4b-5ec2-aae3-0b47457b7ccf
Feed Name: Sekoia.io Blog (archive)
Date Published: 2024-06-03
Date Updated: 2026-07-16
Author: Pierre Le Bourhis, Quentin Bourgue and Sekoia TDR
**PikaBot analysis (May 2024)** — This report details a comprehensive technical analysis of PikaBot, a multi-stage Windows malware loader used by Initial Access Brokers (notably TA577) since Feb 2023, describing its unpacking and reflective-loading stages, extensive anti-analysis (RC4/string obfuscation, junk code, debugger checks, SysWhispers2 direct syscalls), C2 protocol and configuration, distribution chains (phishing, malvertising), associated C2 infrastructure tracking (360+ IPs), and IoCs and MITRE ATT&CK mappings; successful infections have been linked to follow-on Black Basta ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
