Pikachu
Overview
Executive Summary
The Pikachu Worm (often detected as W32/Pikachu.worm) is a classic, early-2000s mass-mailing computer worm designed to appeal to children. Masquerading as a harmless, animated greeting card featuring the popular Pokémon character, its actual payload was highly destructive, attempting to completely delete core Windows operating system directories upon execution.Infection Vector and Technical Capabilities
Pikachu spread almost exclusively via email. It arrived in the victim's inbox with the subject line "Pikachu Pokemon" and a body text claiming "Pikachu is your friend." The attached malicious executable was typically named `pikachuPokemon.exe`. Upon execution, the worm operated in two distinct phases:- Propagation (Mass Mailing): Like many worms of its era (e.g., ILOVEYOU), Pikachu immediately accessed the victim's Microsoft Outlook Address Book. It then utilized Outlook's COM interface to automatically email a copy of itself to every contact in the address book, ensuring rapid, exponential spread across networks.
- Destructive Payload: The worm's secondary function was system vandalism. It modified the `autoexec.bat` file (a critical startup script in older Windows versions like 95, 98, and ME). It added the commands `del C:\WINDOWS\*.* /y` and `del C:\WINDOWS\SYSTEM\*.* /y`, which would attempt to delete the entire Windows directory upon the next system reboot.
Threat Assessment
While the Pikachu worm is entirely obsolete and unable to function on modern Windows operating systems (due to changes in architecture and the deprecation of `autoexec.bat`), it is historically significant. At the time of its release, it caused widespread panic, particularly in educational institutions, due to its child-friendly disguise and destructive payload.Historical Remediation
- Payload Interception: Interestingly, the worm contained a flaw. It often prompted the user with a standard Windows confirmation dialog box ("Are you sure you want to delete these files?") before executing the destructive `del` commands, allowing alert users to cancel the payload.
- Registry and File Cleanup: Remediation involved booting into Safe Mode, deleting the malicious `pikachuPokemon.exe` file, and manually editing the `autoexec.bat` file to remove the destructive commands before rebooting normally.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1566.001 T1485 T1114.003
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1566.001: Scan email attachments for malicious macros, scripts, or suspicious archive files.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_PIKACHU {
meta:
description = "Detects Pikachu (advanced_threat)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "pikachu" ascii wide nocase
$s2 = "w32/pikachu.worm" ascii wide nocase
$s3 = "worm.pikachu" ascii wide nocase
$s4 = "pikachu.exe" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Pikachu Activity
id: 9ce44f88a25272b6d9cbb430ebbcfcf1
status: experimental
description: Detects generic indicators of the pikachu malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*pikachu*"
- "*w32/pikachu.worm*"
- "*worm.pikachu*"
- "*pikachu.exe*"
condition: selection
level: mediumReferences & External Analysis
- Search "pikachu" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Pikachu Advanced_Threat from Windows?
Manual removal of Pikachu is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Pikachu a virus or a Advanced_Threat?
Pikachu is classified as a Advanced_Threat. Unlike traditional viruses that infect files, modern malware like Pikachu typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Pikachu infection?
Symptoms of Pikachu can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: advanced_threat)
Explore other malware families in the same category:
Protect Your Network Against Advanced_Threats
Want to prevent Pikachu and similar threats from compromising your organization? Read our comprehensive defensive guide: Suspect an Infection? What to do.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/pikachu.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.