logo

New Malvertising Campaign Distributing PikaBot Disguised as Popular Software

ID: 4de6826b-2d36-5ca5-94bf-eeb50884b504

STIX ID: report--4de6826b-2d36-5ca5-94bf-eeb50884b504

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Malicious Google search ads are being used to distribute the PikaBot loader (and other loaders such as FakeBat and HiroshimaNukes) by redirecting victims to fake download sites that fingerprint visitors and deliver malicious MSI installers (hosted on services like Dropbox). The campaigns—linked to TA577 and observed delivering Cobalt Strike via PikaBot—use multiple sandbox-evasion checks and may represent a malvertising-as-a-service model; the report also details ParaSiteSnatcher, a Chrome extension framework that intercepts and exfiltrates POST data, highlighting both browser- and extension-based theft vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.