Campaign, Feb 2024 to Feb 2024.View on attack.mitre.org
Pikabot was distributed in Pikabot Distribution February 2024 using malicious emails with embedded links leading to malicious ZIP archives requiring user interaction for follow-on infection. The version of Pikabot distributed featured significant changes over the 2023 variant, including reduced code complexity and simplified obfuscation mechanisms.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
Pikabot Distribution February 2024 passed execution from obfuscated JavaScript files to PowerShell scripts to download and install Pikabot. |
| T1059.007 JavaScript |
Pikabot Distribution February 2024 utilized obfuscated JavaScript files for initial Pikabot payload download. |
| T1566.002 Spearphishing Link |
Pikabot Distribution February 2024 utilized emails with hyperlinks leading to malicious ZIP archive files containing scripts to download and install Pikabot. |
| T1574 Hijack Execution Flow |
Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.