Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Pikabot Malware: Delivery Methods, Evasion, and Impact

Originating in early 2023, Pikabot emerged as a significant malware loader. Over the past year, ThreatLabz has diligently monitored its development and operational methods. Notably, there was a surge in Pikabot’s usage in the latter part of 2023, attributed to a BlackBasta ransomware affiliate adopting Pikabot post the FBI-led Qakbot takedown. However, Pikabot’s activity ceased shortly after Christmas 2023, with version 1.1.19 marking its endpoint.

PoshC2 Explained: Capabilities, Indicators, and Detection

PoshC2 version 6.0, an open-source command and control framework, is notable for its robust capabilities in managing compromised hosts. Accompanying its release, a comprehensive list of Indicators of Compromise (IoCs) and a dedicated GitHub repository have been provided. These resources are designed to assist cybersecurity teams in detecting PoshC2, especially when deployed with its default settings, which less sophisticated attackers often utilize.

What Is gh0st RAT? How It Works, Spreads, and Steals Data

Ghost RAT (Remote Access Trojan) is a type of sophisticated malicious software that operates covertly, enabling unauthorized remote access and control of a victim’s computer system. Often deployed with malicious intent by cybercriminals, Ghost RATs are designed to evade detection and provide the attacker with a range of powerful capabilities, such as data theft, system manipulation, and surveillance.

Havoc Malware: Techniques, Targets, and Threat Overview

Security analysts have noticed a trend among threat actors shifting towards adopting a novel open-source command and control (C2) framework called Havoc as an alternative to paid solutions like Cobalt Strike and Brute Ratel. Developed in the C language and introduced in 2022, Havoc’s Main branch received updates in 2023.