Security News > 2024 > February > Pikabot returns with new tricks up its sleeve

Pikabot returns with new tricks up its sleeve
2024-02-26 13:22

After a short hiatus, Pikabot is back, with significant updates to its capabilities and components and a new delivery campaign.

Pikabot is a loader - a type of malware whose primary function is to serve as a delivery mechanism for other malware.

After the disruption of the Quakbot botnet, Pikabot emerged as an alternative and became particularly active in the second half of 2023.

Its activity stopped in December 2023, possibly due to the recurrence of a new version of Qakbot.

Researchers at Elastic Security Labs observed a new Pikabot campaign, starting on February 8, 2024, which leveraged phishing emails for initial access.

"There are interesting design choices in this new update that we think are the start of a new codebase that will make further improvements over time. While the functionality is similar to previous builds, these new updates have likely broken signatures and previous tooling," Elastic Security Labs researchers noted.


News URL

https://www.helpnetsecurity.com/2024/02/26/pikabot-updates/