ATT&CKCampaignsPikabot Distribution February 2024

Pikabot Distribution February 2024

C0036

Campaign, Feb 2024 to Feb 2024.View on attack.mitre.org

About this campaign

Pikabot was distributed in Pikabot Distribution February 2024 using malicious emails with embedded links leading to malicious ZIP archives requiring user interaction for follow-on infection. The version of Pikabot distributed featured significant changes over the 2023 variant, including reduced code complexity and simplified obfuscation mechanisms.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1059.001
PowerShell

Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot.

T1059.007
JavaScript

Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download.

T1566.002
Spearphishing Link

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

T1574
Hijack Execution Flow

Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software1

References2

  1. Elastic Pikabot 2024 Open source
    Daniel Stepanic & Salim Bitam. (2024, February 23). PIKABOT, I choose you!. Retrieved July 12, 2024.
  2. Zscaler Pikabot 2024 Open source
    Nikolaos Pantazopoulos. (2024, February 12). The (D)Evolution of Pikabot. Retrieved July 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.