
Pikabot Loader Wears a Revoked Bitdefender Certificate
A Pikabot archive-and-payload pair uses a revoked EV code-signing certificate to impersonate Bitdefender's bduserhost.exe, while its C2 layer rotates identical 89-day Let's Encrypt certificates across Contabo, OVH, and a smaller regional host. The activity is tagged to actor 'SafePay' with espionage motivation against a Jordanian government target, despite running on largely commodity loader infrastructure.
A Pikabot infection chain built around a single ZIP archive and its embedded executable is offering a clean look at how one loader family stages, disguises, and calls home in the same breath. The archive — 623KB, delivered under the filename pattern 557390-1743605714.zip — sits and waits: its own behavioral tags mark it as something that "waits for user interaction before running" before it unpacks a single Portable Executable weighing in at 1,459,816 uncompressed bytes.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read