PIK Group
| Primary URL | Location | Industry | pik[.]ru |
Country
Russia
|
Construction
|
|---|
Profile
PIK Group, also known simply as PIK Group, is a Russian real estate development company headquartered in Russia. It is recognized as one of the largest residential developers in the country, focusing on the construction of mass‑market housing projects. The firm operates primarily within the Russian Federation, delivering apartments and integrated urban districts to a broad consumer base. Its business model emphasizes large‑scale panel construction and the use of modern building technologies to reduce costs and accelerate delivery times. PIK Group’s portfolio includes thousands of residential units spread across multiple regions, reflecting a significant footprint in the national housing market. The company also engages in commercial real estate and infrastructure projects, diversifying its offerings beyond pure residential construction. Its market positioning is characterized by a focus on affordability and high turnover, aiming to meet the demand for accessible housing in major Russian cities.
Ownership details of PIK Group are not explicitly provided in the source material, but the entity operates as a publicly traded corporation with shares listed on Russian exchanges. In February 2019, PIK Group was the target of a cyber attack that began with a phishing email containing a malicious ZIP file. The attachment held heavily obfuscated JavaScript posing as order details, which executed a multi‑stage payload. This payload deployed Troldesh ransomware that encrypted files with a ".crypted000007" extension and altered system wallpapers, a cryptocurrency miner that generated roughly 4.89 ZCash for the attackers, and a Trojan‑Heur module enabling credential theft, remote control, and brute‑force attempts against WordPress sites. The attack illustrated a financially motivated approach, combining ransom demands, covert mining, and credential harvesting to achieve immediate profit while maintaining persistent access. The inclusion of noticeable brute‑force activity deviated from typical stealth‑oriented campaigns, suggesting either botnet misuse or a profit‑maximizing tactic rather than state‑sponsored espionage.
