ATT&CKReferencesZscaler Pikabot 2023

Zscaler Pikabot 2023

Brett Stone-Gross & Nikolaos Pantazopoulos. (2023, May 24). Technical Analysis of Pikabot. Retrieved July 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePikabot

Pikabot gathers victim network information through commands such as ipconfig and ipconfig /all.

T1027.003
Steganography
MalwarePikabot

Pikabot loads a set of PNG images stored in the malware's resources section (RCDATA), each with an encrypted section containing portions of the core Pikabot core module. These sections are loaded and decrypted using a bitwise XOR operation with a hardcoded 32 bit key.

T1027.009
Embedded Payloads
MalwarePikabot

Pikabot further decrypts information embedded via steganography using AES-CBC with the same 32 bit key as initial XOR operations combined with the first 16 bytes of the encrypted data as an initialization vector. Other Pikabot variants include encrypted, chunked sections of the stage 2 payload in the initial loader .text section before decrypting and assembling these during execution.

T1055.002
Portable Executable Injection
MalwarePikabot

Pikabot, following payload decryption, creates a process hard-coded into the dropped (e.g., WerFault.exe) and injects the decrypted core modules into it.

T1059.003
Windows Command Shell
MalwarePikabot

Pikabot can execute Windows shell commands via cmd.exe.

T1082
System Information Discovery
MalwarePikabot

Pikabot performs a variety of system checks and gathers system information, including commands such as whoami.

T1106
Native API
MalwarePikabot

Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution.

T1132.001
Standard Encoding
MalwarePikabot

Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.

T1140
Deobfuscate/Decode Files or Information
MalwarePikabot

Pikabot decrypts command and control URIs using ADVobfuscator, and decrypts IP addresses and port numbers with a custom algorithm. Other versions of Pikabot decode chunks of stored stage 2 payload content in the initial payload .text section before consolidating them for further execution. Overall LunarMail is associated with multiple encoding and encryption mechanisms to obfuscate the malware's presence and avoid analysis or detection.

T1480.001
Environmental Keying
MalwarePikabot

Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian.

T1547.001
Registry Run Keys / Startup Folder
MalwarePikabot

Pikabot maintains persistence following system checks through the Run key in the registry.

T1573.001
Symmetric Cryptography
MalwarePikabot

Earlier Pikabot variants use a custom encryption procedure leveraging multiple mechanisms including AES with multiple rounds of Base64 encoding for its command and control communication. Later Pikabot variants eliminate the use of AES and instead use RC4 encryption for transmitted information.

T1622
Debugger Evasion
MalwarePikabot

Pikabot features several methods to evade debugging by analysts, including checks for active debuggers, the use of breakpoints during execution, and checking various system information items such as system memory and the number of processors.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.