Water Curupira is a tracked intrusion cluster associated with distribution of the Pikabot malware through targeted spearphishing campaigns. The activity is characterized by email thread spoofing to increase message credibility and by attachment-based delivery chains that rely on user interaction. Observed lures have included password-protected archive attachments containing heavily obfuscated JavaScript, as well as disk image files containing a shortcut masquerading as a document and a malicious DLL. In some cases, delivery has also involved a PDF attachment containing a malicious link to a Pikabot installer. The infection chain uses social engineering to obtain initial execution, then launches follow-on commands through the Windows command shell, downloads additional payload components with native utilities, and executes the final Pikabot DLL through rundll32. The installer chain includes substantial obfuscation and deobfuscation behavior intended to hinder analysis and evade detection. Based on the available evidence, Water Curupira is best understood as a malware distribution activity cluster focused on phishing-enabled initial access and payload delivery rather than a fully profiled nation-state or ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distribution activity cluster delivering Pikabot via spearphishing, using password-protected ZIPs with obfuscated JavaScript/IMG+LNK, downloading payloads with curl.exe, and executing via rundll32.exe.
Distributes Pikabot via password-protected ZIPs with obfuscated JavaScript and IMG containers with LNK+DLL execution chain.
Conducts spearphishing by spoofing existing email threads (thread hijacking/spoofing) as part of a distribution activity cluster.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.