Home/Threat Actor/PikaBot Operators / Water Curupira
Threat Actor

PikaBot Operators / Water Curupira

pikabot_operators · russia_speaking_organized_cybercrime · active since 2023-Q1

PikaBot Operators / Water Curupira (Trend Micro canonical Water Curupira naming for the distribution-affiliate cluster; Proofpoint TA577.

IBM X-Force Hive0118.

Microsoft Storm- 0464) is a Russia-speaking organized cyber-criminal cluster financially-motivated, active publicly since Q1 2023, one of the most operationally consequential post-FBI-Operation- Duck-Hunt Qakbot-takedown distribution-affiliate clusters in the modern Russia-speaking-organized-cybercrime loader ecosystem.

TA577 historically the primary "letters" affiliate for Qakbot distribution operationally pivoted to PikaBot, DarkGate, and IcedID as replacement payloads following the August 25-29, 2023 FBI Operation Duck Hunt Qakbot international takedown.

signature operational tradecraft includes the Russian/Ukrainian system-language exclusion check (PikaBot halts execution on Russian-language or Ukrainian-language victim systems, one of the strongest Russia-speaking-organized-cybercrime operational-attribution signals), loader + core-module two-component modular architecture, JSON-format C2 communication, ZIP+JS or ZIP+IMG distribution format, email thread-hijacking lure tradecraft inherited from Qakbot-era TA577 distribution, Cobalt Strike Beacon delivery as primary post-compromise payload, and downstream Black Basta ransomware affiliate operations.

industry analysis (Trend Micro initial 2023 research, Darktrace 2023-2024 tracking) hypothesizes that PikaBot may represent a Qakbot-developer regroup following Operation Duck Hunt based on operational similarities (similar distribution methods, multi-stage architecture, Cobalt Strike + Black Basta downstream chain), though no formal attribution confirming Qakbot-developer continuity has been asserted.

PikaBot's Q1 2023 operational emergence predating the August 2023 Qakbot takedown by ~6 months operationally suggests pre-positioning rather than reactive post-takedown response.

caps the post-Qakbot-takedown loader-successor analytical cell in the curated corpus complementing the broader Tier-2.5 loader coverage.

russia_speaking_organized_cybercrime confidence: high 16 aliases MITRE ATT&CK G1037 ↗

Profile

PikaBot Operators / Water Curupira (Trend Micro canonical Water Curupira naming for the distribution-affiliate cluster; Proofpoint TA577.

IBM X-Force Hive0118.

Microsoft Storm- 0464.

malware-family-based industry naming "PikaBot Operators" for the developer cluster) is a Russia-speaking organized cyber-criminal cluster financially-motivated, active publicly since Q1 2023. The cluster operates a developer-vs-distributor two-tier operational structure: (a) a developer cluster (PikaBot developers, no formal public naming) responsible for the modular PikaBot loader malware itself.

(b) a primary distribution-affiliate cluster (Water Curupira / TA577 / Hive0118 / Storm-0464) that operationally distributes PikaBot via large-scale phishing campaigns and additional channels. The cluster is operationally significant in the modern Russia-speaking-organized-cybercrime loader ecosystem as one of the most operationally consequential post-FBI- Operation-Duck-Hunt Qakbot-takedown distribution-affiliate clusters. The TA577 / Water Curupira operational pivot to PikaBot, DarkGate (curated separately as darkgate_operators.yaml), and IcedID (curated separately as icedid_operators.yaml) following the August 25-29, 2023 FBI Operation Duck Hunt Qakbot international takedown is one of the most operationally well-documented organized-cybercrime distribution-affiliate-pivot patterns in modern cyber-threat- intelligence reporting. Operational phases of the cluster's longitudinal history: (1) PIKABOT OPERATIONAL EMERGENCE (Q1 2023). PikaBot was first observed operationally in Q1 2023 with initial phishing campaigns distributing the malware via email-based spam operations. The Q1 2023 emergence predated the August 25-29, 2023 FBI Operation Duck Hunt Qakbot takedown by approximately 6 months, operationally significant because it demonstrates that PikaBot was operationally developed and deployed BEFORE the Qakbot takedown rather than as a post-takedown reactive response. The initial Q1 2023 campaigns lasted until approximately end of June 2023 before a temporary operational quiet period during the summer. (2) POST-QAKBOT-TAKEDOWN OPERATIONAL RAMP-UP (September 2023). Following the August 25-29, 2023 FBI Operation Duck Hunt Qakbot international takedown, PikaBot operations operationally ramped up at significantly increased scale beginning September 2023. TA577 (the primary distribution- affiliate cluster historically responsible for Qakbot "letters"-themed campaign distribution) operationally pivoted to distributing PikaBot, DarkGate, and IcedID as replacement payloads for the disrupted Qakbot. Proofpoint researchers characterized TA577 as "one of the most sophisticated e-crime threat actors" and documented that TA577 "after the QBot disruption announced in August, [...] was inactive for slightly longer than its normal summer break, but then returned to the threat landscape at the end of September to conduct high-volume campaigns delivering a mix of DarkGate and PikaBot before appearing to settle on PikaBot as its preferred payload." (3) TREND MICRO WATER CURUPIRA CANONICAL DISCLOSURE (January 2024). On January 9, 2024, Trend Micro published the canonical industry vendor research-report disclosure of the Water Curupira distribution-affiliate cluster operationally distributing PikaBot. The Trend Micro disclosure documented Water Curupira as operationally distinct from but operationally-overlapping with Proofpoint TA577 (Proofpoint confirmed to The Hacker News that "Water Curupira overlaps with activity it tracks under the name TA577"). The Trend Micro Water Curupira naming added a third-vendor canonical naming to the distribution-affiliate cluster tracking.

(4) MULTI-CHANNEL DISTRIBUTION EXPANSION (December 2023
  • Present). Beginning December 2023, PikaBot distribution operators began using malicious advertising (malvertising) distribution channels targeting businesses through search engine ads, operationally complementing the primary email- spam distribution channel. The malvertising tradecraft included use of specialized services to bypass Google's security measures and establishment of decoy infrastructures. (5) BLACK BASTA RANSOMWARE AFFILIATE CHAIN AND CONTINUED OPERATIONS (2023-2025). PikaBot's primary downstream ransomware-affiliate operational relationship is with the Black Basta ransomware operation. PikaBot infections operationally delivered Cobalt Strike Beacon as the post- compromise framework, which subsequently enabled Black Basta ransomware deployment. Continued operational tempo through 2024-2025 demonstrates sustained operational viability of the PikaBot loader ecosystem.
Signature operational tradecraft includes
  • System-language exclusion check (Russian + Ukrainian): PikaBot performs a system-language check on victim machines and operationally halts execution if the system language is detected as Russian or Ukrainian. This signature "exclude Russia + Ukraine victims" tradecraft is operationally distinctive and one of the strongest Russia-speaking- organized-cybercrime operational-attribution signals observed across PikaBot operations. The Ukrainian-language exclusion was operationally inverted across some adjacent organized-cybercrime clusters following the February 2022 Russia-Ukraine war operational ruptures, but PikaBot operationally maintains Ukrainian-language exclusion.
  • Loader + core-module two-component architecture: PikaBot's modular architecture consists of a small initial- stage loader component and a larger main-functionality core module. The two-component architecture enables operational flexibility and incremental capability deployment.
  • JSON-format C2 communication: PikaBot collects victim system information (system details for operator pre-engagement reconnaissance) and exfiltrates the data to command-and- control servers in JSON format. The JSON format enables structured operator-facing C2 dashboarding.
  • ZIP+JS or ZIP+IMG distribution format: signature initial-access delivery format using ZIP archive attachments containing JavaScript files or IMG (disk image) files as execution launchpads. The format enables evasion of traditional email-security platform attachment-scanning mechanisms.
  • Email thread-hijacking lure tradecraft: signature TA577 distribution tradecraft inherited from Qakbot distribution era. PikaBot phishing operations exploit legitimate email threads to inject malicious lure content as apparent replies to actual prior correspondence.
  • Cobalt Strike Beacon delivery as primary post-compromise payload: PikaBot operationally serves as initial-access vector for Cobalt Strike Beacon deployment, which subsequently enables hands-on-keyboard operator activity and ransomware- affiliate operations.
  • Multi-channel distribution: email-spam (primary), malvertising via Google search ads (December 2023+), potentially other channels. Multi-channel distribution operationally extends reach beyond email-only campaigns.
  • Anti-analysis tradecraft: anti-VM, anti-sandbox, anti-debug detection routines operationally consistent across PikaBot versions. Trend Micro and Cisco Talos analysis document sophisticated anti-analysis tradecraft. The cluster is operationally significant as one of the most operationally consequential post-Qakbot-takedown loader ecosystems in the modern Russia-speaking-organized- cybercrime ecosystem. Industry analysis hypothesizes that PikaBot may represent a Qakbot-developer regroup following Operation Duck Hunt, based on operational similarities with Qakbot including similar distribution methods, multi- stage attack architecture, frequent Cobalt Strike Beacon delivery, and downstream Black Basta ransomware affiliate relationships. No formal attribution confirming Qakbot- developer continuity has been publicly asserted by any government cybersecurity authority or industry vendor, but the operational similarities are operationally consistent with the regroup hypothesis. The continuity of TA577 as the primary distribution affiliate across Qakbot.
  • PikaBot is operationally consistent with the regroup hypothesis but is also operationally consistent with TA577 simply pivoting to alternative loaders in the post-takedown era. The cluster operationally caps the post-Qakbot-takedown loader- successor analytical cell in this curated corpus, complementing the broader Tier-2.5 loader-as-a-service coverage (qakbot_operators.yaml, emotet_operators.yaml, icedid_operators.yaml, bumblebee_exotic_lily.yaml, darkgate_operators.yaml) by providing operational analysis of the modern era's most operationally documented loader- successor pattern.

Aliases

16
water curupirawater-curupirawatercurupirata577ta-577hive0118hive-0118storm-0464storm0464pikabotpika_botpika botpikabot_loaderpikabot loaderpikabot_operatorspikabot operators

Notable Campaigns

7
2024-2025Continued Operations and Modular Evolution (2024-2025)
2024Trend Micro Water Curupira Canonical Disclosure (January 9, 2024)
2023-presentOperational Similarities With Qakbot, Possible Developer-Regroup Hypothesis
2023-2024Malvertising Distribution Channel Innovation (December 2023)
2023-2024Black Basta Ransomware Affiliate Chain (2023-2024)
2023PikaBot Operational Emergence and Initial Campaigns (Q1 2023)
2023Post-Qakbot-Takedown Operational Ramp-Up (September 2023)

Attribution & Reporting

Attributed by
Trend MicroProofpointMicrosoft Threat Intelligence CenterIBM X-ForceMandiantCrowdStrikeCisco TalosCybereasonDarktraceRed CanarySymantec / Broadcom Threat Hunter TeamSecureWorks Counter Threat UnitPalo Alto Networks Unit 42Trustwave SpiderLabsHiveProCofenseHP Wolf SecurityReliaQuestSentinelOneCheck Point ResearchDeutsche Telekom CERT (Telekom Security)ESETKaspersky GReAT
Key reporting
reportTrend Micro: A Look Into the PikaBot Spam Wave Campaign (January 9, 2024), canonical Water Curupira industry-vendor research-report disclosure
reportProofpoint: TA577 Returns to the Threat Landscape with PikaBot and DarkGate (October-December 2023)
reportDarktrace: PikaBot, Battling a Fast-Moving Loader Malware in the Wild (March 2024)
reportCisco Talos: PikaBot Anti-Analysis Tradecraft Analysis
reportPalo Alto Networks Unit 42: TA577 + PikaBot Continued Threat Intelligence Tracking (2023-2024)
reportElastic Security Labs: PikaBot Deep Dive Technical Analysis
reportZscaler ThreatLabz: PikaBot Operational Analysis
reportCybereason: PikaBot Threat Analysis
reportHivePro: PikaBot Malware Unleashes Threat via Malvertising (December 2023)
reportMicrosoft Threat Intelligence: Storm-0464 Tracking, TA577 / Water Curupira / PikaBot Continued Operations
reportIBM X-Force: Hive0118 Operational Profile
reportMandiant: PikaBot + TA577 Operational Tracking
reportCrowdStrike: PikaBot + Wizard Spider Successor Ecosystem Documentation
reportRed Canary: PikaBot Threat Profile (2024+)
reportSymantec / Broadcom: TA577 + PikaBot Continued Tracking
reportSecureWorks Counter Threat Unit: PikaBot Operational Profile
reportTrustwave SpiderLabs: PikaBot Anti-Analysis Tradecraft
reportCofense: PikaBot Phishing Campaign Tracking (2023-2024)
reportDeutsche Telekom CERT (Telekom Security): TA577 PikaBot Distribution Documentation (September 2023+)
reportMalpedia Malware Profile: Win.PikaBot
reportVirus Bulletin Conference 2024: PikaBot, Life, Times, and Death of a Modular Loader Malware

Operational

State sponsor

Russia-speaking organized cyber-criminal cluster, financially- motivated. The cluster's operational identification consists of (a) a malware-developer cluster (PikaBot developers, no formal public naming) responsible for the modular PikaBot loader malware itself.

and (b) a primary distribution- affiliate cluster (Trend Micro Water Curupira / Proofpoint TA577 / IBM X-Force Hive0118 / Microsoft Storm-0464) that operationally distributes PikaBot via large-scale phishing campaigns. The two-tier developer-vs-distributor operational structure is operationally consistent with the broader Russia-speaking-organized-cybercrime loader ecosystem pattern. The Russia-speaking operational basing is operationally confirmed by a signature operational pattern documented across multiple industry vendor analyses: PikaBot performs a system-language check on victim machines and operationally halts execution if the system language is detected as Russian or Ukrainian. This signature "exclude Russia + Ukraine victims" tradecraft is operationally distinctive among modern organized-cybercrime malware families and is consistent with Russia-speaking-organized-cybercrime operator self-preservation under historical Russia-jurisdiction operational tolerance patterns (operators avoid prosecutorial attention by not victimizing CIS-region targets). The Ukrainian exclusion is operationally notable, the Ukrainian- language exclusion was operationally inverted across some adjacent organized-cybercrime clusters following the February 2022 Russia-Ukraine war operational ruptures, but PikaBot operationally maintains Ukrainian-language exclusion. Distribution-affiliate cluster TA577 / Water Curupira / Hive0118 / Storm-0464 is one of the most operationally significant post-Qakbot-takedown distribution-affiliate clusters in the modern Russia-speaking-organized-cybercrime ecosystem, historically the primary "letters" affiliate for Qakbot distribution (Proofpoint TA577 historically tracked as letters-themed campaign-ID Qakbot affiliate). The TA577 operational pivot to PikaBot, DarkGate, and IcedID following the August 25-29, 2023 FBI Operation Duck Hunt Qakbot takedown is one of the most operationally well- documented organized-cybercrime distribution-affiliate- pivot patterns in modern cyber-threat-intelligence reporting. Industry analysis (Trend Micro, Darktrace) and community researcher observation strongly suggests PikaBot may be operationally and behaviorally related to Qakbot, shared similar distribution methods, multi-stage attack patterns, frequent Cobalt Strike Beacon delivery payloads, and other operational commonalities, and may represent a Qakbot-developer regroup following the Operation Duck Hunt takedown. No formal attribution confirming Qakbot-developer continuity has been publicly asserted by any government cybersecurity authority or industry vendor, but the operational similarities are operationally consistent with the regroup hypothesis. Downstream ransomware-affiliate operational relationships include the Black Basta ransomware operation (signature 2023-2024 affiliate relationship, curated separately as black_basta.yaml in this corpus) and adjacent post-Conti-ecosystem operators.

Motivations
loader_as_a_service_revenue, access_resale_to_ransomware_affiliates, data_theft_and_extortion, credential_harvesting_for_follow_on_operations, cobalt_strike_beacon_delivery_for_ransomware_staging
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
METERPRETERSHARPHOUND
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin