Skip to content

Pikabot

Pikabot is a widely deployed malware loader used by malicious actors to deliver follow-on payloads such as Cobalt Strike and ransomware.

Profile source: Mallory opens in a new tab

Pikabot

Family profile

Pikabot is a widely deployed malware loader used by malicious actors to deliver follow-on payloads such as Cobalt Strike and ransomware. It has been associated with the loader/dropper ecosystem targeted by Operation Endgame and has been used by threat actors including TA577 and Black Basta; leaked Black Basta chats also referenced mecor as the developer of Pikabot. Reported delivery methods include phishing-driven chains using password-protected ZIP archives containing heavily obfuscated JavaScript, IMG files containing an LNK masquerading as a Word document plus a malicious DLL, and February 2024 campaigns where obfuscated JavaScript handed execution to PowerShell to download and install Pikabot. Elastic observed a February 8 campaign in which phishing emails linked to ZIP archives containing obfuscated JavaScript that used PowerShell Invoke-WebRequest to download a Pikabot loader from gloverstech[.]com, saved as %SYSTEMDRIVE%\Users\Public\Jrdhtjydhjf.exe.

The malware uses staged loading and strong obfuscation. Reported variants include stage 2 payload chunks embedded in the loader .text section, later decrypted and assembled during execution, and steganography-protected embedded data decrypted with AES-CBC after initial XOR operations. In the updated variant analyzed by Elastic, the loader reconstructed the Pikabot core from base64-encoded chunks in the .data section, decrypted chunks with RC4, decompressed them, and injected the core into a suspended ctfmon.exe process using direct syscalls and anti-debugging checks. The core supports post-compromise command-and-control access including command execution, discovery, file and registry modification, and PE or shellcode injection. Pikabot fingerprints victims, generates a victim UUID from system volume number, hostname, and username, and collects host data including username, computer name, processor details, display device data, domain controller information, memory usage, window dimensions, OS version, and process listings. One analyzed sample created mutex {6F70D3AF-34EF-433C-A803-E83654F6FD7C} and terminated on Russian or Ukrainian language systems.

For communications, Pikabot uses base64 encoding together with symmetric encryption to obfuscate C2 traffic. During initial check-in it transmits collected system information encrypted with RC4. Elastic reported an updated core using RC4-plus-byte-swapping network encryption, plaintext runtime configuration in memory, and HTTPS communications over non-standard ports such as 2967 and 2223 with the User-Agent string "Microsoft Office/14.0 (Windows NT 6.1; Microsoft Outlook 14.0.7166; Pro)". Reported campaign observables include SHA-256 2f66fb872c9699e04e54e5eaef982784b393a5ea260129a1e2484dd273a5a88b for Opc.zip, SHA-256 ca5fb5814ec62c8f04936740aabe2664b3c7d036203afbd8425cd67cf1f4b79d for grepWinNP3.exe, domains gloverstech[.]com and entrevientos.com[.]ar, and C2 servers 158.220.80[.]167:2967, 139.84.237[.]229:2967, 104.129.55[.]104:2223, and 85.239.243[.]155:5000.

Reported operators

Threat actors

2 named in public reporting
TA577

More recently, they have delivered Pikabot and DarkGate malware.

MITRE ATT&CK

Pikabot in ATT&CK

48 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.