high_confidence

Water Curupira Pikabot Distribution

[Pikabot](https://attack.mitre.org/software/S1145) was distributed in [Water Curupira Pikabot Distribution](https://attack.mitre.org/campaigns/C0037) throughout 2023 by an entity linked to BlackBasta ransomware deployment via email attachments. This activity followed the take-down of [QakBot](https://attack.mitre.org/software/S0650), with several technical overlaps and similarities with [QakBot](https://attack.mitre.org/software/S0650), indicating a possible connection. The identified activity led to the deployment of tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154), while coinciding with campaigns delivering [DarkGate](https://attack.mitre.org/software/S1111) and [IcedID](https://attack.mitre.org/software/S0483) en route to ransomware deployment.(Citation: TrendMicro Pikabot 2024)

Start date
1 January 2023
End date
1 December 2023
Techniques
10

Attributed actors

Techniques (10)

command-and-control1
T1105Ingress Tool Transfer
execution5
T1059.003Windows Command Shell
T1204.002Malicious File
T1059.007JavaScript
T1204.001Malicious Link
T1204User Execution
initial-access1
T1566.001Spearphishing Attachment
reconnaissance1
T1589.002Email Addresses
stealth2
T1140Deobfuscate/Decode Files or Information
T1218.011Rundll32

Indicators of compromise

No IOCs linked to this campaign yet.