Rise of Pikabot: The New Cyber Threat in the Post-Qakbot Era

Share This Post

A recent cybersecurity report highlights the emergence of a new malware, Pikabot, associated with Black Basta ransomware attacks. The threat actor, Water Curupira, is using Pikabot in a widespread phishing campaign targeting organizations. Pikabot is considered a potential replacement for the Qakbot Trojan, which was taken down in August 2023 during Operation Duck Hunt. Despite Qakbot’s takedown, which affected around 700,000 infected machines, Pikabot has surfaced with similar functionality.

Pikabot campaigns typically start with phishing emails using thread-jacking, a technique that involves hijacking existing email threads to seem legitimate. These emails contain malicious attachments that, when opened, lead to the downloading and execution of Pikabot. Notably, Pikabot avoids attacking systems using Russian or Ukrainian languages, indicating possible geographic affiliations of the threat actor.

Trend Micro, the cybersecurity firm reporting these findings, advises users to exercise caution with emails, especially from unfamiliar sources. They recommend verifying sender identities and the legitimacy of email content, as well as maintaining updated systems and regular backups to mitigate risks from such threats.

Link:

https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks



Reach out to our incident response team for help

More To Explore

Information Security News – 4/14/2025

Oracle Confirms “Obsolete Servers” Hacked Article link: https://www.bleepingcomputer.com/news/security/oracle-says-obsolete-servers-hacked-denies-cloud-breach/    Phishing Kits Now Vet Victims in Real-Time Before Stealing Credentials Article link: https://www.bleepingcomputer.com/news/security/phishing-kits-now-vet-victims-in-real-time-before-stealing-credentials/    Neptune RAT

Information Security News – 4/7/2025

Criminal Group Claims Responsibility for Cyberattack on Minnesota Casino Article Link: https://cdcgaming.com/brief/cybersecurity-incident-at-minnesota-tribal-community-casino-prompts-shutdown/ As CISA Downsizes, Where Can Enterprises Get Support? Article Link: https://www.darkreading.com/cybersecurity-operations/roundtable-cisa-downsizes-where-can-enterprises-look-support Oracle Privately

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.