Rise of Pikabot: The New Cyber Threat in the Post-Qakbot Era

Share This Post

A recent cybersecurity report highlights the emergence of a new malware, Pikabot, associated with Black Basta ransomware attacks. The threat actor, Water Curupira, is using Pikabot in a widespread phishing campaign targeting organizations. Pikabot is considered a potential replacement for the Qakbot Trojan, which was taken down in August 2023 during Operation Duck Hunt. Despite Qakbot’s takedown, which affected around 700,000 infected machines, Pikabot has surfaced with similar functionality.

Pikabot campaigns typically start with phishing emails using thread-jacking, a technique that involves hijacking existing email threads to seem legitimate. These emails contain malicious attachments that, when opened, lead to the downloading and execution of Pikabot. Notably, Pikabot avoids attacking systems using Russian or Ukrainian languages, indicating possible geographic affiliations of the threat actor.

Trend Micro, the cybersecurity firm reporting these findings, advises users to exercise caution with emails, especially from unfamiliar sources. They recommend verifying sender identities and the legitimacy of email content, as well as maintaining updated systems and regular backups to mitigate risks from such threats.

Link:

https://www.darkreading.com/cyberattacks-data-breaches/pikabot-malware-qakbot-replacement-black-basta-attacks



Reach out to our incident response team for help

More To Explore

Information Security News – 6/9/2025

Microsoft and CrowdStrike Partner to Link Threat Actor Names Article link: https://www.bleepingcomputer.com/news/security/microsoft-and-crowdstrike-partner-to-link-hacking-group-names/     Why IAM Should Be the Starting Point for AI-Driven Cybersecurity Article link:

Information Security News – 6/2/2025

Why Layoffs Increase Cybersecurity Risks Article Link: https://www.helpnetsecurity.com/2025/05/26/layoffs-cybersecurity-risks/ The CISO’s Dilemma: Balancing Access, Security, and Operational Continuity Article Link: https://www.forbes.com/councils/forbestechcouncil/2025/05/27/the-cisos-dilemma-balancing-access-security-and-operational-continuity/ Massive Data Breach Exposes 184

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.