Skip to main content
Mallory
Financially Motivated1 malware family

Water Curupira

Also known asWater Curupira

Water Curupira is a threat activity cluster associated with distribution of the Pikabot malware via spearphishing. The campaign uses email thread spoofing of existing conversations to increase credibility and deliver malicious content. Initial access is achieved primarily through spearphishing attachments (MITRE ATT&CK T1566.001), including password-protected ZIP archives containing heavily obfuscated JavaScript installers (T1059.007) and, in some cases, a PDF attachment containing a malicious link to a Pikabot installer. Execution requires user interaction (T1204). The installation chain includes JavaScript that launches follow-on commands via cmd.exe (T1059.003), uses curl.exe to download the Pikabot payload from an external server (T1105), saves the payload to the victim’s temporary directory, and executes the final payload as a DLL via rundll32.exe (T1218.011). The DLL is executed using named exports “Crash” or “Limit,” depending on the variant. The chain includes obfuscation and deobfuscation behaviors (T1140). The activity is also associated with gathering victim identity information in the form of email addresses (T1589.002) to support targeting and phishing workflows.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.