logo

PikaBot Resurfaces with Streamlined Code and Deceptive Tactics

ID: d3352845-4652-5748-97c6-0c6b0a2ffca1

STIX ID: report--d3352845-4652-5748-97c6-0c6b0a2ffca1

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Zscaler researchers observed a new development cycle for PikaBot (v1.18.32) where the operators simplified obfuscation, changed network command/encryption behavior, and stored the bot configuration in plaintext memory; PikaBot is being distributed via phishing and malvertising as an initial-access loader/backdoor used to drop tools like Cobalt Strike. The report also references a Proofpoint disclosure of an active Azure account-takeover campaign using tailored phishing to harvest credentials for exfiltration, internal/external phishing, and financial fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.