Attackers used malicious Google search ads impersonating AnyDesk to deliver PikaBot, redirecting victims through traffic-filtering and fingerprinting infrastructure before serving a digitally signed MSI installer from Dropbox. Researchers said the chain included JavaScript-based anti-analysis checks and likely virtualization detection, echoing earlier fake software ad campaigns that used spoofed AnyDesk pages, MSI installers, and staged payload delivery to infect Windows systems.
PikaBot is a loader designed to fetch and execute additional malware, with commands for shell execution, payload retrieval, shellcode launch, and system profiling over encrypted HTTPS communications. Its emergence in malvertising expands a malware family already linked to initial-access activity and ransomware delivery ecosystems, reinforcing a broader criminal model in which loaders such as PikaBot, IcedID, and TrickBot establish footholds that are later used for tools like Cobalt Strike and, in some cases, hands-on ransomware deployment.

Pull IOCs and campaign context straight into your stack.
27 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes cited Cofense observations that malspam campaigns delivering DarkGate and PikaBot increased after the August 2023 takedown of the QakBot botnet. The shift suggested other loaders were filling the gap left by QakBot.
Malwarebytes said PikaBot was first identified in February 2023 by Unit 42 as a possible Matanbuchus drop from a malspam campaign. This marked the malware family's initial identification in public reporting.
A Google search for AnyDesk on December 14, 2022 led through ad and traffic-distribution infrastructure to a fake AnyDesk page that served a malicious ZIP and MSI installer. Executing the MSI installed IcedID and led to follow-on payload retrieval associated with Cobalt Strike and Sliver and/or DonutLoader.
On November 15, 2021, Cryptolaemus, GData, and Advanced Intel observed TrickBot dropping a new Emotet loader onto infected devices. Researchers said the operators were rebuilding Emotet through TrickBot infrastructure in what Cryptolaemus called 'Operation Reacharound.'
Proofpoint cited an FBI report stating that Avaddon operators increasingly obtained initial access through remote access portals such as RDP and VPN rather than direct email. The FBI report was anchored to May 2021.
German law enforcement used seized Emotet infrastructure to deliver a module that uninstalled Emotet from infected devices. The action occurred on April 25, 2021.
Proofpoint assessed with high confidence that TA577 was associated with a Sodinokibi ransomware infection initiated through malicious Office attachments that downloaded IcedID. The event was explicitly anchored to March 2021.
Check Point reported that TrickBot affected 2.2% of organizations worldwide in 2021 and analyzed modules including injectDll, tabDll, and pwgrabc. It also said TrickBot targeted customers of about 60 high-profile financial, cryptocurrency, and technology brands.
Proofpoint reported that ransomware was rarely delivered directly by email and was increasingly enabled through initial access facilitators distributing loaders and banking trojans. It said banking trojans represented almost 20% of malware observed in identified campaigns in the first half of 2021.
An international law enforcement operation disrupted Emotet infrastructure and prevented further infections. Multiple sources anchor this disruption to January 2021.
Microsoft announced action with telecommunications providers worldwide to disrupt key TrickBot infrastructure used to distribute the malware and activate follow-on payloads such as ransomware. The company also detailed a representative intrusion chain showing operators gaining control of a device about 8.5 hours after document execution.
Proofpoint assessed with high confidence that TA551 IcedID implants were associated with Maze and Egregor ransomware events. The association was explicitly described for 2020.
Proofpoint assessed with high confidence that TA569 was associated with WastedLocker ransomware campaigns using the SocGholish fake update framework. The activity was explicitly anchored to 2020.
Group-IB Threat Intelligence previously published research on IcedID. Later analysis referenced this as prior work before describing a newer steganography-heavy version.
Between 2018 and 2020, Emotet was one of the most prolific distributors of malware that later enabled ransomware infections. It commonly spread other payloads including TrickBot and QakBot.
IBM X-Force researchers first described the IcedID banking trojan. Later reporting referenced this as the malware family's initial public identification.
Necurs malspam campaigns used DDE-enabled Office documents to download QtBot, which then delivered either TrickBot or Locky depending on the victim's location. Palo Alto Networks said it observed more than 4 million unique QtBot sessions beginning on October 19, 2017.
TrickBot was first observed in 2016 as a banking trojan and successor to Dyre. Early reporting described it as a developing financial malware family with browser hooks, persistence, and limited targeting.
After analyzing the campaign, defenders reported the malicious ads and payload URLs to Google and Dropbox. The reporting followed discovery of the AnyDesk-themed malvertising chain distributing PikaBot.
Researchers observed a malvertising campaign using Google search ads impersonating AnyDesk to distribute PikaBot through a signed MSI hosted on Dropbox. The chain used filtering, fingerprinting, and infrastructure resembling earlier FakeBat malvertising activity.
Malwarebytes reported that Proofpoint later named the malware PikaBot and attributed its distribution to TA577. This established the malware's commonly used name and an early distribution attribution.
DCSO CyTec analyzed PikaBot as a new loader malware family with separate loader and core components, anti-debugging, some anti-VM logic, and HTTPS JSON-based C2 traffic encrypted with Base64 and AES-CBC. The researchers said there was insufficient evidence to confirm a relationship with Matanbuchus.
After Emotet's return, Abuse.ch released a list of command-and-control servers used by the new botnet and reported that more than 246 infected devices were already acting as C2 servers. Researchers warned administrators to block the associated IP addresses.
VinCSS detected and blocked a phishing campaign that inserted a malicious attachment into an existing email exchange using a compromised partner mail server account. The infection chain used a password-protected ZIP, embedded VBA and JavaScript, regsvr32 execution, and multi-stage DLL loading before injecting TrickBot into wermgr.exe.
The DFIR Report described a recent intrusion in which attackers manually executed a TrickBot DLL on one endpoint, established persistence, performed reconnaissance and credential theft, and launched two Cobalt Strike Beacons. No lateral movement or follow-on mission activity was observed before the actors left the network.
Trend Micro reported a malware campaign propagating the fileless BazarBackdoor through phishing emails and disguised executables. Researchers attributed it to the actors behind TrickBot based on similarities in code, crypters, infrastructure, and delivery methods.
Researchers observed a newer TrickBot campaign whose webinject configuration expanded targeting to Germany and the UK in addition to Canada, Australia, and New Zealand. The campaign also showed more mature dynamic webinjects and functional static redirects.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 265 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
16 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcecofense.com
Open sourcezscaler.com
Open sourcegroup-ib.com
Open sourcemicrosoft.com
Open sourcetrendmicro.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcef5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.