Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Pikabot

111
Global rank
48 infographic chevron month
Month rank
66 infographic chevron week
Week rank
0
IOCs

Pikabot is a trojan malware with a focus on loader capabilities. Pikabot is also used for other activities, such as executing commands on the infected system. The earlier versions of the malware made use of extensive code obfuscation to evade detection. Upon infection, it collects system information and sends it to command-and-control servers.

Loader
Type
ex-USSR
Origin
1 February, 2023
First seen
2 September, 2026
Last seen

How to analyze Pikabot with ANY.RUN

Type
ex-USSR
Origin
1 February, 2023
First seen
2 September, 2026
Last seen

IOCs

IP addresses
185.199.111.133
89.208.104.175
104.192.108.20
198.251.89.144
178.16.52.221
61.249.139.64
140.82.121.3
119.59.120.15
91.92.242.236
64.89.163.22
196.251.107.186
103.45.66.107
211.149.230.178
104.20.29.150
2.16.241.213
212.232.22.87
101.126.11.168
163.181.92.209
172.66.47.100
121.41.25.85
Hashes
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0
a3d5715a81f2fbeb5f76c88c9c21eeee87142909716472f911ff6950c790c24d
2aab13d49b60001de3aa47fb8f7251a973faa7f3c53a3840cdf5fd0b26e9a09f
7c37e942ce92fc48457fc6d484e8ed788da7b8b23689c0ed4601d26b0f629336
e78b678846c177786e70e29d5111359d4aff20d9ac5935fad2be87b17d7f9fc9
cae57a60c4d269cd1ca43ef143aedb8bfc4c09a7e4a689544883d05ce89406e7
2546dcffc5ad854d4ddc64fbf056871cd5a00f2471cb7a5bfd4ac23b6e9eedad
a736269f5f3a9f2e11dd776e352e1801bc28bb699e47876784b8ef761e0062db
e682dfcdde010f6e15bae0d843696f6ae8d5a85e75441660b782789ee747f075
da1798c0a49b991fbda674f02007b0a3be4703e2b07ee540539db7e5bf983278
941ebf1dc12321bbe430994a55f6e22a1b83cea2fa7d281484ea2dab06353112
3ae96f73d805e1d3995253db4d910300d8442ea603737a1428b613061e7f61e7
dace2a571c147da773724738bb0b80d39c430cce12f770210d8f270e958db773
4e64f4e40d8cbff082b37186c831af4b49e3131c62c00a0cf53e0a6e7e24ac2b
0e22bc2bf7184dfdb55223a11439304a453fb3574e3c9034a6497af405c628ef
f864e8640c98b65c6c1b9b66a850661e8397ed6e66b06f4424396275488af1be
Domains
muaklekcoop.com
www.teknoarge.com
shhsift.click
www.ojang.pe.kr
pvsa.gxfugy.cn
elisans.novayonetim.com
3.zhzy999.net3.zhzy999.net
dl.dzqzd.com
1h.vuregyy1.ru
projetodegente.com
www.medises.co.kr
cdn.gomlab.com
dl.ijinshan.com
ed75a310.infinityindians.pages.dev
hobobot.net
31.128.173.853.zhzy999.net31.128.173.853.zhzy999.net
imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
www.myvcart.com
www.namuvpn.com
class1004.dothome.co.kr
URLs
http://5.230.201.18/bin/support.client.exe
http://5.230.201.18/bin/screenconnect.clientsetup.exe
http://178.16.54.109/spmm.exe
http://91.92.242.236/files-129312398/files/file_785424af55f8958c.exe
http://178.16.54.109/main.exe
http://178.16.54.109/spm.exe
http://178.16.54.109/nmm.exe
http://178.16.54.109/ot.exe
http://91.92.242.236/files-129312398/files/file_14ff2f15194a832e.exe
http://91.92.242.236/files-129312398/files/file_018d7b156998810c.exe
http://91.92.242.236/files-129312398/files/file_8eb65d0dcf9d4880.exe
http://178.16.54.109/c.exe
http://91.92.242.236/files-129312398/files/file_3357265371188090.exe
http://178.16.54.109/nm.exe
http://91.92.242.236/files-129312398/files/file_30391bd0ced7aa24.exe
http://37.77.150.214:8080/msi/setup_cf4cb3a3.msi
http://217.60.241.32/bin/support.client.exe
http://217.60.241.32/bin/screenconnect.clientsetup.exe
http://192.162.199.149/uploads/8323ff95090049d3826616b94eed7cd8.exe
http://192.162.199.149/uploads/26bd033dff764587836ef1b2e13d79eb.exe
Last Seen at
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 1374
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 1930
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 6441
comments 0

What is Pikabot malware?

Pikabot, a loader malware, made its first appearance in the cybersecurity realm in February 2023. This malicious software is recognized for its wide array of anti-analysis features and flexible capabilities that have made it a popular choice among many attackers.

The malware functions through two key modules: the loader and the core. The loader initiates the malware's operations, while the core houses its primary functionalities. Pikabot shows signs of continuous evolution, as its latest version appeared in February 2024, exhibiting notable differences from its original builds.

The resemblances between Pikabot and Qakbot have led to assumptions that they could be the work of the same malware developers. Pikabot has also been utilized in campaigns orchestrated by the threat actor TA577, where it was disseminated in conjunction with the DarkGate malware.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Pikabot malware technical details

Criminals leverage Pikabot for various harmful activities which include:

  • Executing Commands via cmd.exe: Pikabot can execute commands on the compromised system using the Windows Command Prompt (cmd.exe).
  • Terminating the Current Process: Pikabot has the capability to self-terminate.
  • Injecting and Executing Downloaded Shellcode: The malware can download shellcode from its command-and-control (C2) server and inject it into other running processes.
  • Injecting Downloaded DLL and EXE Files: Pikabot can also download and inject DLL and executable files.

In its earlier iterations, the Pikabot trojan utilized a combination of AES-CBC and RC4 key to encrypt strings. The new version demonstrates a shift towards less complex obfuscation and only occasional use of RC4.

Another notable difference between the early variants of the malware and its newest form is the approach to storing a configuration. While the first builts contained hardcoded configs, the newer iterations tend to download them from the command and control (C2) server.

The Pikabot malware is particularly skilled at evading sandbox detection. One way it does this is by postponing its execution until the sandbox analysis period has expired. The malware also integrates junk code among legitimate instructions to further complicate analysis.

Pikabot uses regex to dynamically generate file names and other data. This lets the malware hide its code and evade detection by security tools that rely on signatures.

Pikabot initiates its operations by registering the compromised host with the C2 servers. This process involves gathering system information and submitting it to the C2 server via an HTTPS POST request. The gathered data encompasses. The data collected by Pikabot is encoded using standard Base64 and then encrypted using AES. The malware collects the following information about the system:

  • Network Information: This includes details about the network connections, IP addresses, etc.
  • User and Group Information: Pikabot collects usernames and other related details.
  • Windows Build Information: The malware gathers data about the Windows operating system installed on the system, including the version and build number.
  • Generic Host Information: This includes various details about the system's hardware and software configuration, such as the amount of available RAM.
  • Additional Host Information: Depending on the commands received from the command-and-control (C2) server, Pikabot can collect extra info about the compromised system, including screenshots.

Pikabot execution process

Let’s upload a sample of Pikabot to the ANY.RUN sandbox to conduct a Pikabot malware analysis sessions and observe its execution process in detail.

Pikabot malware initiates its execution chain by leveraging phishing emails or malicious downloads to infiltrate a system. Once inside, it employs PowerShell scripts or macros to download additional payloads from a remote server.

Pikabot then uses living-off-the-land techniques, such as exploiting legitimate system processes like "ctfmon.exe," to evade detection and maintain persistence. This process, commonly used for language and input services, is hijacked to execute malicious code while appearing benign.

The malware establishes communication with its command-and-control (C2) server, receiving instructions and exfiltrating sensitive data. It can also spread laterally across networks, exploiting vulnerabilities or using stolen credentials.

Throughout its execution, Pikabot employs various obfuscation and evasion techniques to avoid detection by security solutions.

Pikabot process graph in ANY.RUN Pikabot process graph demonstrated in ANY.RUN

Pikabot malware distribution methods

Just as in the case of other widespread malware, such as Remcos and NjRAT, Pikabot has been observed to be distributed primarily via phishing emails. Attackers usually employ multi-stage attacks that begin with an email that ask users to perform certain activities, such as clicking a link or opening a weaponized attachment. From there, the infection begins.

Another notable attack involving Pikabot occurred in 2023 when attackers utilized malvertising. As part of their campaign, they employed Google Ads to promote a fake website with a download link for AnyDesk, a remote desktop software. After running the installer file, the victim’s system became compromised and infected with Pikabot.

Conclusion

Pikabot is a sophisticated trojan malware that has the potential to significantly disrupt the affected infrastructure. Thanks to its anti-analysis features, it can be a challenge for certain security solutions to detect it. Therefore, it is impossible to use reliable solutions that timely implement updates to keep up with the new version of Pikabot.

Use ANY.RUN, a cloud-based sandbox, for analyzing suspicious files and links to identify Pikabot and other malware families. The service lets you gain an in-depth look at the behavior of any malware in a completely safe and secure environment. ANY.RUN generates detailed reports on the analyzed threats that contain all the essential information, including Pikabot IOCs (indicators of compromise) and TTPs, needed for making better security decisions.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More