Pikabot

S1145

Malware.View on attack.mitre.org

About this malware

Pikabot is a backdoor used for initial access and follow-on tool deployment active since early 2023. Pikabot is notable for extensive use of multiple encoding, encryption, and defense evasion mechanisms to evade defenses and avoid analysis. Pikabot has some overlaps with QakBot, but insufficient evidence exists to definitively link these two malware families. Pikabot is frequently used to deploy follow on tools such as Cobalt Strike or ransomware variants.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1016
System Network Configuration Discovery

Pikabot gathers victim network information through commands such as ipconfig and ipconfig /all.

T1027.003
Steganography

Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key.

T1027.009
Embedded Payloads

Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader .text section before decrypting and assembling these during execution.

T1027.011
Fileless Storage

Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine.

T1041
Exfiltration Over C2 Channel

During the initial Pikabot command and control check-in, Pikabot will transmit collected system information encrypted using RC4.

T1055.002
Portable Executable Injection

Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it.

T1055.003
Thread Execution Hijacking

Pikabot can create a suspended instance of a legitimate process (e.g., ctfmon.exe), allocate memory within the suspended process corresponding to Pikabot's core module, then redirect execution flow via `SetContextThread` API so that when the thread resumes the Pikabot core module is executed.

T1059.003
Windows Command Shell

Pikabot can execute Windows shell commands via cmd.exe.

T1082
System Information Discovery

Pikabot performs a variety of system checks and gathers system information, including commands such as whoami.

T1087.001
Local Account

Pikabot will retrieve the name of the user associated with the thread under which the malware is executing.

T1106
Native API

Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution.

T1132.001
Standard Encoding

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1140
Deobfuscate/Decode Files or Information

Pikabot decrypts command and control URIs using ADVobfuscator, and decrypts IP addresses and port numbers with a custom algorithm. Other versions of Pikabot decode chunks of stored stage 2 payload content in the initial payload .text section before consolidating them for further execution. Overall LunarMail is associated with multiple encoding and encryption mechanisms to obfuscate the malware's presence and avoid analysis or detection.

T1480.001
Environmental Keying

Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian.

T1482
Domain Trust Discovery

Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution.

View all 21 procedure examples

Groups that use it1

Campaigns2

References3

  1. Elastic Pikabot 2024 Open source
    Daniel Stepanic & Salim Bitam. (2024, February 23). PIKABOT, I choose you!. Retrieved July 12, 2024.
  2. Logpoint Pikabot 2024 Open source
    Swachchhanda Shrawan Poudel. (2024, February). Pikabot: 
 A Sophisticated and Modular Backdoor Trojan with Advanced Evasion Techniques. Retrieved July 12, 2024.
  3. Zscaler Pikabot 2023 Open source
    Brett Stone-Gross & Nikolaos Pantazopoulos. (2023, May 24). Technical Analysis of Pikabot. Retrieved July 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.