Researchers detailed how Pikabot has evolved into a heavily obfuscated malware loader and core backdoor that uses layered string protection, dynamic API resolution, anti-analysis checks, and stealthy process injection. Recent reverse-engineering shows Pikabot decrypts strings through per-string RC4, modified Base64, and AES-CBC, while newer tooling can now automate recovery of keys, IVs, and encrypted arrays from samples. Analysts said the malware disguises itself as SearchProtocolHost.exe, walks the PEB to locate kernel32.dll, hashes API names, and uses indirect syscalls such as NtAllocateVirtualMemory, NtWriteVirtualMemory, and NtResumeThread to inject its core module into a suspended legitimate process.
The recovered functionality shows Pikabot can profile hosts, enumerate processes, execute commands, manipulate files and the registry, and communicate with command-and-control servers over WinINet using HTTP POST requests. Earlier loader samples also established persistence with a scheduled task and a registry-stored PowerShell downloader that fetched a DLL, decoded it from Base64, and launched it with regsvr32, while newer samples extracted payload components from PNG resources before decryption and injection. Reporting on distribution linked Pikabot to spam thread-hijacking campaigns, malicious attachments and links, and malvertising that impersonated AnyDesk, with operators using commands such as whoami.exe /all, ipconfig.exe /all, and netstat.exe -aon to survey compromised systems.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz analyzed Pikabot version 1.8.32 and documented changes including plaintext in-memory configuration storage, a shift from RC4-plus-AES-CBC string protection to mostly stack-built or RC4-only strings, and repeated anti-debugging checks. The report also described a redesigned C2 protocol using raw RC4-encrypted packets, per-host 32-byte session keys, randomized byte swapping, and defined command IDs for execution, file writing, and code injection.
ThreatLabz published a technical method for automating Pikabot string deobfuscation with IDA microcode, including extraction of AES key and IV material, RC4-encrypted arrays, string sizes, and per-string RC4 keys from samples.
Pulsedive reported that Pikabot had been distributed through spam campaigns and AnyDesk-themed malvertising, used anti-analysis and CIS-language checks, and contacted C2 infrastructure after collecting host information. The report also noted that as of January 2024 only one Pikabot sample had been shared on MalwareBazaar, uploaded on January 3, 2024.
A reverse-engineering report on an updated Pikabot loader described the malware reconstructing its core module from 12 PNG resources, decrypting it, and injecting it into a suspended SearchProtocolHost.exe process using indirect syscalls while performing anti-analysis checks.
A follow-up OALABS analysis described automating recovery of encrypted strings from the new Pikabot core module using instruction-pattern matching and a custom memory-only emulator, revealing APIs, persistence paths, command strings, and likely configuration elements.
OALABS reported that an updated Pikabot version had been observed in the wild, with stronger anti-analysis features, layered RC4/Base64/AES-CBC string protection, host profiling, WinINet-based HTTP POST communications, and loader injection into SearchProtocolHost.exe.
Pulsedive said Pikabot usage became more prevalent after the August 2023 law-enforcement takedown of Qakbot.
A deep technical analysis of Pikabot was published by d01a, documenting the malware's behavior and implementation details during its early 2023 activity period. This represents a separate public technical disclosure between the February tiny-loader analysis and the later November updates.
An OALABS analysis published on February 26, 2023 detailed a Pikabot tiny loader that used encrypted stack strings, dynamic API resolution, a VirtualBox artifact check, registry-stored PowerShell, and scheduled-task persistence to download and execute a DLL from 37.1.215.220 via regsvr32.
Pulsedive reported that Pikabot had been active since early 2023 as an emerging malware loader used to gain access to compromised environments and execute commands or deliver additional tools.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcezscaler.com
Open sourceblog.pulsedive.com
Open sourcekienmanowar.wordpress.com
Open sourceresearch.openanalysis.net
Open sourced01a.github.io
Open sourceresearch.openanalysis.net
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.