logo

PikaBot: a Guide to its Deep Secrets and Operations

ID: e7665462-cf4b-5ec2-aae3-0b47457b7ccf

STIX ID: report--e7665462-cf4b-5ec2-aae3-0b47457b7ccf

Feed Name: Sekoia.io Blog (archive)

Threat Score
78/100

Date Published: 2024-06-03

Date Updated: 2026-07-16

Author: Pierre Le Bourhis, Quentin Bourgue and Sekoia TDR

...
...

**PikaBot analysis (May 2024)** — This report details a comprehensive technical analysis of PikaBot, a multi-stage Windows malware loader used by Initial Access Brokers (notably TA577) since Feb 2023, describing its unpacking and reflective-loading stages, extensive anti-analysis (RC4/string obfuscation, junk code, debugger checks, SysWhispers2 direct syscalls), C2 protocol and configuration, distribution chains (phishing, malvertising), associated C2 infrastructure tracking (360+ IPs), and IoCs and MITRE ATT&CK mappings; successful infections have been linked to follow-on Black Basta ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.