Threat Advisory

PikaBot Reappears with Streamlined Code and False Tactics

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Pikabot is a malware loader first identified in early 2023, Over the past year, Researchers have been following the expansion of Pikabot and its modus operandi. There was an important increase in usage of Pikabot in the second half of 2023, subsequent the FBI-led takedown of Qakbot. This spike in Pikabot usage suggests its adoption by affiliates of the BlackBasta ransomware, possibly as a replacement for Qakbot in initiating unauthorized access. However, Pikabot shortly ceased operations around Christmas 2023, according with its version 1.1.19 release. Notably, its rebirth in February 2024 marked a new phase characterized by substantial code and structural modifications. The developers opted for a simpler codebase, avoiding advanced obfuscation techniques prevalent in previous iterations. Furthermore, Pikabot now stores all configuration elements in a single memory block, similar to Qakbot.[/subscribe_to_unlock_form]

Summary:

Pikabot is a malware loader first identified in early 2023, Over the past year, Researchers have been following the expansion of Pikabot and its modus operandi. There was an important increase in usage of Pikabot in the second half of 2023, subsequent the FBI-led takedown of Qakbot. This spike in Pikabot usage suggests its adoption by affiliates of the BlackBasta ransomware, possibly as a replacement for Qakbot in initiating unauthorized access. However, Pikabot shortly ceased operations around Christmas 2023, according with its version 1.1.19 release. Notably, its rebirth in February 2024 marked a new phase characterized by substantial code and structural modifications. The developers opted for a simpler codebase, avoiding advanced obfuscation techniques prevalent in previous iterations. Furthermore, Pikabot now stores all configuration elements in a single memory block, similar to Qakbot.[emaillocker id="1283"]

Pikabot's latest version showcases notable alterations from previous iterations. One key change involves the simplification of string obfuscation techniques, replacing complex encryption algorithms with more straightforward methods. Anti-analysis measures, such as junk instructions and anti-debugging techniques, persist but do not demonstrate significant advancements. The malware employs anti-sandbox evasion tactics and language detection to avoid analysis and detection, reflecting a continued effort to evade security measures. Regarding network communications, Pikabot undergoes substantial changes in its protocol, including the registration of compromised hosts to the C2 server. Pikabot collects comprehensive system information, encrypts it using the RC4 algorithm, and sends it to the C2 server via a POST request. Notably, Pikabot replaces the JSON format in its network packets with a raw format, further complicating analysis and detection. Despite these modifications, Pikabot's registration process remains vulnerable to exploitation due to the reuse of network RC4 keys and the absence of fixed round numbers for encoding data, enhancing its resilience against automated detection and analysis techniques.

Pikabot remains an active and evolving threat in the cybersecurity landscape. Its resurgence in February 2024, coupled with significant codebase modifications, underscores the adaptability and persistence of its developers. By simplifying encryption techniques and refining anti-analysis measures, Pikabot aims to enhance its stealth and evasion capabilities. However, incomplete features and ongoing development suggest that the malware is still in a transitional phase, with additional changes likely forthcoming. As organizations and cybersecurity professionals continue to monitor and combat threats like Pikabot, understanding its evolving tactics and techniques remains paramount in mitigating risks and safeguarding systems against malicious intrusions.

Threat Profile:

              

References:

The following reports contain further technical details:

https://thehackernews.com/2024/02/pikabot-resurfaces-with-streamlined.html

 

[/emaillocker]
crossmenu