logo

Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware

ID: 6222312e-6add-5ea9-bf6b-706812bc21d9

STIX ID: report--6222312e-6add-5ea9-bf6b-706812bc21d9

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-09

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Water Curupira (associated with TA577) ran high-volume malspam campaigns in 2023 distributing the PikaBot loader, which fetches Cobalt Strike and enables follow-on Black Basta ransomware deployments; campaigns leveraged email-thread hijacking and ZIP attachments and actively avoided Russian/Ukrainian environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.