The group behind the PikaBot malware has resurfaced with significant changes to the software, in a case that has been described as “devolution.”
See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

The PikaBot malware, discovered by the cybersecurity firm in May 2023, is a malicious loader and backdoor that can execute commands and inject payloads from a control (C2) server as well as allow the attacker to control the infected computer.
It is also known to crash if the system language is Russian or Ukrainian, indicating that the operators are based in either Russia or Ukraine.
In recent months, both the PikaBot malware and another loader named DarkGate have emerged as attractive alternatives for threat actors like Water Curupira (also known as TA577) to gain initial access to target networks through phishing and to drop Cobalt Strike.
Zscaler's analysis of a new version of PikaBot (version 1.18.32) observed this month has revealed a continued emphasis on obfuscation, albeit with simpler encryption algorithms, and the insertion of junk command code between valid commands, as part of its efforts to resist analysis.
See also: New Python variant of Chaes Malware targets banking and logistics industries
Another critical modification seen in the latest version is that the entire bot configuration – similar to that of QakBot – is stored in plain text in a single block of memory instead of encrypting and decrypting each element during execution.
A third change concerns the C2 server's network communications, with the malware's creators adjusting the command identifiers and the encryption algorithm used to secure traffic.

The development came as Proofpoint alerted to a cloud account takeover (ATO) attack that has targeted dozens of Microsoft Azure environments and compromised hundreds of user accounts, including those belonging to senior executives.
The activity, ongoing since November 2023, targets users with tempting baits containing fake files containing links to malicious phishing websites for credential collection and data extraction, internal and external phishing, and financial fraud.
See also: Mobile malware: A major risk for businesses
How can one protect themselves from backdoor attacks?
The first and most important strategy for protecting against backdoor attacks is awareness and education. Users need to be aware of the techniques attackers use to install backdoors and how they can counter them.
Additionally, using reliable security software is crucial. Antivirus programs can detect and remove backdoor attacks, while also providing real-time protection. Regularly updating your software and operating system is also an effective way to protect against backdoor attacks. Updates often include security patches that fix vulnerabilities that attackers can exploit.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, using strong passwords and enabling two-factor authentication can provide additional protection. Strong passwords make it harder for attackers to compromise user accounts, while two-factor authentication requires an extra verification step to access an account.
Source: thehackernews
