Skip to content

Botnet

Pikabot

Introducing Pikabot, an emerging malware family that comprises a downloader/installer, a loader, and a core backdoor component.

Pikabot is a Windows botnet.

Background

Pikabot is a newer malware family made up of a downloader/installer, a loader, and a core backdoor module. Though still early in its development, it already exhibits advanced evasion, injection, and anti-analysis tradecraft. Its loader, in particular, packs a range of refined anti-debugging and anti-VM checks drawn from the open-source Al-Khaser project and hides its payload using steganography. Pikabot further relies on a custom C2 framework and accepts a broad set of commands covering host enumeration and sophisticated secondary payload injection.


Source: Malpedia (Fraunhofer FKIE).