Description
Pikabot is a loader and backdoor that has been active since early 2023. Its components include a downloader and installer, a loader, and a core backdoor, and it resists analysis through extensive encoding, encryption, and defense evasion, including anti-debugging and anti-VM measures inspired by the open source Al-Khaser project and steganography that conceals its payload. Infections frequently lead to the deployment of follow on tools such as Cobalt Strike or ransomware variants.
Stats
- First seen
- August 2023
- Last seen
- October 2026
Also known as
PikaBot
MITRE ATT&CK techniques
21 techniques across 6 tactics.
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| ByteCode-JAVA.Trojan.Pikabot |
| Document-HTML.Downloader.PikaBot |
| Document-HTML.Trojan.Pikabot |
| Document-HTML.Trojan.PikaBot |
| Document-Office.Downloader.PikaBot |
| Document-Office.Trojan.PikaBot |
| Document-PDF.Trojan.Pikabot |
| Document-Word.Trojan.Pikabot |
| Script-JS.Downloader.PikaBot |
| Script-JS.Trojan.Pikabot |

