Water Curupira
Water Curupira is a threat activity cluster associated with distribution of the Pikabot malware via spearphishing. The campaign uses email thread spoofing of existing conversations to increase credibility and deliver malicious content. Initial access is achieved primarily through spearphishing attachments (MITRE ATT&CK T1566.001), including password-protected ZIP archives containing heavily obfuscated JavaScript installers (T1059.007) and, in some cases, a PDF attachment containing a malicious link to a Pikabot installer. Execution requires user interaction (T1204). The installation chain includes JavaScript that launches follow-on commands via cmd.exe (T1059.003), uses curl.exe to download the Pikabot payload from an external server (T1105), saves the payload to the victim’s temporary directory, and executes the final payload as a DLL via rundll32.exe (T1218.011). The DLL is executed using named exports “Crash” or “Limit,” depending on the variant. The chain includes obfuscation and deobfuscation behaviors (T1140). The activity is also associated with gathering victim identity information in the form of email addresses (T1589.002) to support targeting and phishing workflows.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distribution activity cluster delivering Pikabot via spearphishing, using password-protected ZIPs with obfuscated JavaScript/IMG+LNK, downloading payloads with curl.exe, and executing via rundll32.exe.
Distributes Pikabot via password-protected ZIPs with obfuscated JavaScript and IMG containers with LNK+DLL execution chain.
Conducts spearphishing by spoofing existing email threads (thread hijacking/spoofing) as part of a distribution activity cluster.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.