Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Pikabot

110
Global rank
69 infographic chevron month
Month rank
154 infographic chevron week
Week rank

Pikabot is a trojan malware with a focus on loader capabilities. Pikabot is also used for other activities, such as executing commands on the infected system. The earlier versions of the malware made use of extensive code obfuscation to evade detection. Upon infection, it collects system information and sends it to command-and-control servers.

Loader
Type
ex-USSR
Origin
1 February, 2023
First seen
2 September, 2026
Last seen

How to analyze Pikabot with ANY.RUN

Type
ex-USSR
Origin
1 February, 2023
First seen
2 September, 2026
Last seen

IOCs

IP addresses
185.199.111.133
89.208.104.175
104.192.108.20
198.251.89.144
178.16.52.221
61.249.139.64
140.82.121.3
119.59.120.15
91.92.242.236
64.89.163.22
196.251.107.186
103.45.66.107
211.149.230.178
104.20.29.150
2.16.241.213
212.232.22.87
101.126.11.168
163.181.92.209
172.66.47.100
121.41.25.85
Hashes
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0
a3d5715a81f2fbeb5f76c88c9c21eeee87142909716472f911ff6950c790c24d
2aab13d49b60001de3aa47fb8f7251a973faa7f3c53a3840cdf5fd0b26e9a09f
7c37e942ce92fc48457fc6d484e8ed788da7b8b23689c0ed4601d26b0f629336
e78b678846c177786e70e29d5111359d4aff20d9ac5935fad2be87b17d7f9fc9
cae57a60c4d269cd1ca43ef143aedb8bfc4c09a7e4a689544883d05ce89406e7
2546dcffc5ad854d4ddc64fbf056871cd5a00f2471cb7a5bfd4ac23b6e9eedad
a736269f5f3a9f2e11dd776e352e1801bc28bb699e47876784b8ef761e0062db
e682dfcdde010f6e15bae0d843696f6ae8d5a85e75441660b782789ee747f075
da1798c0a49b991fbda674f02007b0a3be4703e2b07ee540539db7e5bf983278
941ebf1dc12321bbe430994a55f6e22a1b83cea2fa7d281484ea2dab06353112
3ae96f73d805e1d3995253db4d910300d8442ea603737a1428b613061e7f61e7
dace2a571c147da773724738bb0b80d39c430cce12f770210d8f270e958db773
4e64f4e40d8cbff082b37186c831af4b49e3131c62c00a0cf53e0a6e7e24ac2b
0e22bc2bf7184dfdb55223a11439304a453fb3574e3c9034a6497af405c628ef
f864e8640c98b65c6c1b9b66a850661e8397ed6e66b06f4424396275488af1be
Domains
muaklekcoop.com
www.teknoarge.com
shhsift.click
www.ojang.pe.kr
pvsa.gxfugy.cn
elisans.novayonetim.com
3.zhzy999.net3.zhzy999.net
dl.dzqzd.com
1h.vuregyy1.ru
projetodegente.com
www.medises.co.kr
cdn.gomlab.com
dl.ijinshan.com
ed75a310.infinityindians.pages.dev
hobobot.net
31.128.173.853.zhzy999.net31.128.173.853.zhzy999.net
imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
www.myvcart.com
www.namuvpn.com
class1004.dothome.co.kr
URLs
http://5.230.201.18/bin/support.client.exe
http://5.230.201.18/bin/screenconnect.clientsetup.exe
http://178.16.54.109/spmm.exe
http://91.92.242.236/files-129312398/files/file_785424af55f8958c.exe
http://178.16.54.109/main.exe
http://178.16.54.109/spm.exe
http://178.16.54.109/nmm.exe
http://178.16.54.109/ot.exe
http://91.92.242.236/files-129312398/files/file_14ff2f15194a832e.exe
http://91.92.242.236/files-129312398/files/file_018d7b156998810c.exe
http://91.92.242.236/files-129312398/files/file_8eb65d0dcf9d4880.exe
http://178.16.54.109/c.exe
http://91.92.242.236/files-129312398/files/file_3357265371188090.exe
http://178.16.54.109/nm.exe
http://91.92.242.236/files-129312398/files/file_30391bd0ced7aa24.exe
http://37.77.150.214:8080/msi/setup_cf4cb3a3.msi
http://217.60.241.32/bin/support.client.exe
http://217.60.241.32/bin/screenconnect.clientsetup.exe
http://192.162.199.149/uploads/8323ff95090049d3826616b94eed7cd8.exe
http://192.162.199.149/uploads/26bd033dff764587836ef1b2e13d79eb.exe
Last Seen at
Last Seen at

Recent blog posts

post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 3858
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 9554
comments 0
post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 8737
comments 0

What is Pikabot malware?

Pikabot, a loader malware, made its first appearance in the cybersecurity realm in February 2023. This malicious software is recognized for its wide array of anti-analysis features and flexible capabilities that have made it a popular choice among many attackers.

The malware functions through two key modules: the loader and the core. The loader initiates the malware's operations, while the core houses its primary functionalities. Pikabot shows signs of continuous evolution, as its latest version appeared in February 2024, exhibiting notable differences from its original builds.

The resemblances between Pikabot and Qakbot have led to assumptions that they could be the work of the same malware developers. Pikabot has also been utilized in campaigns orchestrated by the threat actor TA577, where it was disseminated in conjunction with the DarkGate malware.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Pikabot malware technical details

Criminals leverage Pikabot for various harmful activities which include:

  • Executing Commands via cmd.exe: Pikabot can execute commands on the compromised system using the Windows Command Prompt (cmd.exe).
  • Terminating the Current Process: Pikabot has the capability to self-terminate.
  • Injecting and Executing Downloaded Shellcode: The malware can download shellcode from its command-and-control (C2) server and inject it into other running processes.
  • Injecting Downloaded DLL and EXE Files: Pikabot can also download and inject DLL and executable files.

In its earlier iterations, the Pikabot trojan utilized a combination of AES-CBC and RC4 key to encrypt strings. The new version demonstrates a shift towards less complex obfuscation and only occasional use of RC4.

Another notable difference between the early variants of the malware and its newest form is the approach to storing a configuration. While the first builts contained hardcoded configs, the newer iterations tend to download them from the command and control (C2) server.

The Pikabot malware is particularly skilled at evading sandbox detection. One way it does this is by postponing its execution until the sandbox analysis period has expired. The malware also integrates junk code among legitimate instructions to further complicate analysis.

Pikabot uses regex to dynamically generate file names and other data. This lets the malware hide its code and evade detection by security tools that rely on signatures.

Pikabot initiates its operations by registering the compromised host with the C2 servers. This process involves gathering system information and submitting it to the C2 server via an HTTPS POST request. The gathered data encompasses. The data collected by Pikabot is encoded using standard Base64 and then encrypted using AES. The malware collects the following information about the system:

  • Network Information: This includes details about the network connections, IP addresses, etc.
  • User and Group Information: Pikabot collects usernames and other related details.
  • Windows Build Information: The malware gathers data about the Windows operating system installed on the system, including the version and build number.
  • Generic Host Information: This includes various details about the system's hardware and software configuration, such as the amount of available RAM.
  • Additional Host Information: Depending on the commands received from the command-and-control (C2) server, Pikabot can collect extra info about the compromised system, including screenshots.

Pikabot execution process

Let’s upload a sample of Pikabot to the ANY.RUN sandbox to conduct a Pikabot malware analysis sessions and observe its execution process in detail.

Pikabot malware initiates its execution chain by leveraging phishing emails or malicious downloads to infiltrate a system. Once inside, it employs PowerShell scripts or macros to download additional payloads from a remote server.

Pikabot then uses living-off-the-land techniques, such as exploiting legitimate system processes like "ctfmon.exe," to evade detection and maintain persistence. This process, commonly used for language and input services, is hijacked to execute malicious code while appearing benign.

The malware establishes communication with its command-and-control (C2) server, receiving instructions and exfiltrating sensitive data. It can also spread laterally across networks, exploiting vulnerabilities or using stolen credentials.

Throughout its execution, Pikabot employs various obfuscation and evasion techniques to avoid detection by security solutions.

Pikabot process graph in ANY.RUN Pikabot process graph demonstrated in ANY.RUN

Pikabot malware distribution methods

Just as in the case of other widespread malware, such as Remcos and NjRAT, Pikabot has been observed to be distributed primarily via phishing emails. Attackers usually employ multi-stage attacks that begin with an email that ask users to perform certain activities, such as clicking a link or opening a weaponized attachment. From there, the infection begins.

Another notable attack involving Pikabot occurred in 2023 when attackers utilized malvertising. As part of their campaign, they employed Google Ads to promote a fake website with a download link for AnyDesk, a remote desktop software. After running the installer file, the victim’s system became compromised and infected with Pikabot.

Conclusion

Pikabot is a sophisticated trojan malware that has the potential to significantly disrupt the affected infrastructure. Thanks to its anti-analysis features, it can be a challenge for certain security solutions to detect it. Therefore, it is impossible to use reliable solutions that timely implement updates to keep up with the new version of Pikabot.

Use ANY.RUN, a cloud-based sandbox, for analyzing suspicious files and links to identify Pikabot and other malware families. The service lets you gain an in-depth look at the behavior of any malware in a completely safe and secure environment. ANY.RUN generates detailed reports on the analyzed threats that contain all the essential information, including Pikabot IOCs (indicators of compromise) and TTPs, needed for making better security decisions.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More