PikaBot Malware Deployed Alongside DarkGate

computer malware

Phishing campaigns deploying malware families like DarkGate and PikaBot are employing strategies reminiscent of previous attacks involving the now-defunct QakBot trojan. According to a report from Cofense shared with The Hacker News, these tactics include initiating infections through compromised email threads, utilizing URLs with distinct patterns to restrict user access, and employing an infection chain closely resembling that of QakBot delivery.

The chosen malware families also align with the expectations for use by QakBot affiliates. QakBot, also known as QBot and Pinkslipbot, was dismantled as part of Operation Duck Hunt in August.

The adoption of DarkGate and PikaBot in these campaigns is unsurprising, given their capability to serve as conduits for delivering additional payloads to compromised hosts, making them appealing options for cybercriminals. Zscaler had previously highlighted the parallels between PikaBot and QakBot in a May 2023 analysis, noting similarities in distribution methods, campaigns, and malware behaviors.

DarkGate, on its part, employs advanced techniques to elude antivirus detection, including keystroke logging, PowerShell execution, and the implementation of a reverse shell that enables operators to remotely control an infected host, according to a technical report from Sekoia.

In a comprehensive analysis of the high-volume phishing campaign, Cofense revealed that it targets a diverse array of sectors. The attack chains involve booby-trapped URLs within hijacked email threads, directing users to a ZIP archive. This archive contains a JavaScript dropper that connects to a second URL to download and execute either the DarkGate or PikaBot malware.

A notable variation of the attacks utilizes Excel add-in (XLL) files instead of JavaScript droppers to deliver the final payloads. A successful infection by DarkGate or PikaBot could result in the deployment of advanced crypto mining software, reconnaissance tools, ransomware, or any other malicious file chosen by the threat actors, as reported by Cofense.

November 22, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.