ATT&CKReferencesElastic Pikabot 2024

Elastic Pikabot 2024

Daniel Stepanic & Salim Bitam. (2024, February 23). PIKABOT, I choose you!. Retrieved July 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples20

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwarePikabot

Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader .text section before decrypting and assembling these during execution.

T1027.011
Fileless Storage
MalwarePikabot

Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine.

T1041
Exfiltration Over C2 Channel
MalwarePikabot

During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4.

T1055.003
Thread Execution Hijacking
MalwarePikabot

Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed.

T1059.001
PowerShell
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot.

T1059.007
JavaScript
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download.

T1082
System Information Discovery
MalwarePikabot

Pikabot performs a variety of system checks and gathers system information, including commands such as whoami.

T1087.001
Local Account
MalwarePikabot

Pikabot will retrieve the name of the user associated with the thread under which the malware is executing.

T1106
Native API
MalwarePikabot

Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution.

T1132.001
Standard Encoding
MalwarePikabot

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1140
Deobfuscate/Decode Files or Information
MalwarePikabot

Pikabot decrypts command and control URIs using ADVobfuscator, and decrypts IP addresses and port numbers with a custom algorithm. Other versions of Pikabot decode chunks of stored stage 2 payload content in the initial payload .text section before consolidating them for further execution. Overall LunarMail is associated with multiple encoding and encryption mechanisms to obfuscate the malware's presence and avoid analysis or detection.

T1480.001
Environmental Keying
MalwarePikabot

Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian.

T1482
Domain Trust Discovery
MalwarePikabot

Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution.

T1497.001
System Checks
MalwarePikabot

Pikabot performs a variety of system checks to determine if it is running in an analysis environment or sandbox, such as checking the number of processors (must be greater than two), and the amount of RAM (must be greater than 2GB).

T1566.002
Spearphishing Link
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot.

T1571
Non-Standard Port
MalwarePikabot

Pikabot uses non-standard ports, such as 2967, 2223, and others, for HTTPS command and control communication.

T1573.001
Symmetric Cryptography
MalwarePikabot

Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information.

T1574
Hijack Execution Flow
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched.

T1620
Reflective Code Loading
MalwarePikabot

Pikabot reflectively loads stored, previously encrypted components of the PE file into memory of the currently executing process to avoid writing content to disk on the executing machine.

T1622
Debugger Evasion
MalwarePikabot

Pikabot features several methods to evade debugging by analysts, including checks for active debuggers, the use of breakpoints during execution, and checking various system information items such as system memory and the number of processors.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.