Pikabot Malware Surfaces as Qakbot Replacement for Black Basta Attacks

siteadmin January 9, 2024

The threat actor associated with Black Basta ransomware attacks has been using a new loader, Pikabot, to conduct a widespread phishing campaign aimed at gaining access to corporate networks. These attacks are designed to drop backdoors like Cobalt Strike, leading to Black Basta ransomware attacks. Called ‘Water Curupira’, the campaign has evolved to use thread-jacked emails for legitimacy, increasing the likelihood of victims engaging with the threat actor and downloading the malware.