PikaBot Resurfaces with Streamlined Code and Deceptive Tactics
ID: d3352845-4652-5748-97c6-0c6b0a2ffca1
STIX ID: report--d3352845-4652-5748-97c6-0c6b0a2ffca1
Feed Name: The Hacker News
Zscaler researchers observed a new development cycle for PikaBot (v1.18.32) where the operators simplified obfuscation, changed network command/encryption behavior, and stored the bot configuration in plaintext memory; PikaBot is being distributed via phishing and malvertising as an initial-access loader/backdoor used to drop tools like Cobalt Strike. The report also references a Proofpoint disclosure of an active Azure account-takeover campaign using tailored phishing to harvest credentials for exfiltration, internal/external phishing, and financial fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
