Netskope Threat Labs

Pikabot

ATP Sandbox Adv. Heuristics

Pikabot is a loader and backdoor that has been active since early 2023. Its components include a downloader and installer, a loader, and a core backdoor, and it resists analysis through extensive encoding, encryption, and defense evasion, including anti-debugging and anti-VM measures inspired by the open source Al-Khaser project and steganography that conceals its payload. Infections frequently lead to the deployment of follow on tools such as Cobalt Strike or ransomware variants.

First seen
August 2023
Last seen
October 2026
PikaBot

21 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1082System Information Discovery
  • T1087Account Discovery
  • T1482Domain Trust Discovery

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
ByteCode-JAVA.Trojan.Pikabot
Document-HTML.Downloader.PikaBot
Document-HTML.Trojan.Pikabot
Document-HTML.Trojan.PikaBot
Document-Office.Downloader.PikaBot
Document-Office.Trojan.PikaBot
Document-PDF.Trojan.Pikabot
Document-Word.Trojan.Pikabot
Script-JS.Downloader.PikaBot
Script-JS.Trojan.Pikabot