PikaBot is a modular Windows malware loader first observed in 2023. It provides initial access for financially motivated intrusions and delivers additional payloads, including Cobalt Strike, that support follow-on ransomware operations. Its architecture separates a loader from a core component responsible for host profiling, command-and-control communications, and execution of operator-supplied commands and payloads.
PikaBot can download and execute executable files and DLLs, run shell commands and shellcode, enumerate processes, and inject payloads into other processes. It collects host and domain information, including operating-system details, usernames, hardware characteristics, running processes, and security software. Observed loaders inject the core into legitimate Windows processes, using suspended-process execution and direct or indirect system calls to evade conventional API monitoring. Defense-evasion measures include control-flow obfuscation, encrypted strings, API hashing, debugger and analysis-tool detection, and virtual-machine checks. Variants terminate on systems configured with selected CIS-region language identifiers, including Russian and Ukrainian. A tiny-loader variant stores a PowerShell downloader in the registry and uses a recurring scheduled task for persistence and subsequent-stage execution.
Distribution commonly uses high-volume phishing campaigns and hijacked email threads containing malicious links or archives. JavaScript downloaders invoke PowerShell to retrieve and execute the loader; other observed delivery chains use Excel add-ins, Visual Basic scripts, and Windows shortcuts. Some campaigns restrict payload retrieval by browser or geographic location to reduce unwanted exposure. Command-and-control traffic is encrypted, with protocols varying between versions.
PikaBot has been distributed by TA577 and used by Black Basta operators across campaigns targeting multiple industries. It gained prominence in the initial-access ecosystem following QakBot's 2023 disruption. PikaBot infrastructure was among the targets of the multinational Operation Endgame disruption in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Pikabot:” Loader malware with extensive defense evasion capabilities.
It was quickly nicknamed Pikabot. Pikabot consists of two components: loader/injector and core module. Core module then performs malicious behaviors, including gathering information about the victim machine, connecting to command and control server to receive and execute arbitrary commands, downloading and injecting other malware.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious code employs heavy obfuscation, utilizing a technique where a JMP follows each assembly instruction; the core also uses junk instructions and obfuscated global variables.
Bot commands include PE injection in a remote process (0x36C) and shellcode injection in a remote process (0x792).
The core retrieves the name of the user associated with the PIKABOT thread and generates a victim UUID using the hostname and username.
116 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
111 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Establishes initial access and delivers additional capabilities supporting ransomware, remote control, and data theft. Described as one of the loaders filling the gap after QakBot's disruption and targeted by Operation Endgame in 2024.
Referenced as an example botnet distributed via drive-by download techniques.
Pikabot2
A malware family in the dropper/loader ecosystem referenced as a prior law-enforcement target.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.