FILEMembers
FILE

Pikabot Loader Poses as Trend Micro DNS Module

A Win32 DLL flagged by 60 of 78 engines as trojan.pikabot/zusy carries a fake "Trend Micro Osprey" product string despite being unsigned. Syscall-level anti-debug tricks and sandbox-stalling code sit alongside network indicators that still trip Feodo Tracker and TrickBot JA3 rules.

Jul 17, 2026, 13:37 (UTC+9)Last seenJul 17, 2026Severity77ByCTX TeamActorSafePayIOC16MITRE13RegionsUS

A Win32 DLL now flagged by 60 of 78 engines as trojan.pikabot/zusy carries a product string reading "Trend Micro Osprey" and a copyright block crediting "Trend Micro Incorporated" — grafted onto a binary that is unsigned and delivers a Pikabot loader. The disguise sits alongside syscall-level anti-debug tricks and sandbox-stalling code, and the sample's associated network indicators still trip Feodo Tracker and TrickBot JA3 fingerprint rules — legacy botnet signatures riding on infrastructure…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence