BazarCall is a cybercrime collective associated with the broader Conti syndicate and is described as one of the smaller groups that emerged as Conti members dispersed into semi-independent cells and infiltrated or took over other operations. It has been characterized as an exfiltration-focused group rather than a conventional ransomware encryption operation, aligning it more closely with data-theft and extortion activity than with standalone file-encrypting campaigns. BazarCall is linked in reporting to the same criminal ecosystem that included Conti, TrickBot, BazarBackdoor, Hive, Black Basta, BlackCat, Karakurt, BlackByte, AvosLocker, Quantum, ZEON, and Hello Kitty. The group’s known role within that ecosystem is tied to post-compromise monetization through theft of victim data and extortion pressure rather than direct encryption. Its association with the Conti network indicates overlap with a Russian-based cybercrime milieu that operated globally and relied on shared personnel, access brokers, and affiliated sub-groups. Publicly available information in this context does not establish a distinct independent malware family, victimology profile, or stable organizational structure for BazarCall beyond its identification as a Conti-linked collective focused on data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a social-engineering/cybercrime collective that former Conti members allegedly infiltrated or took over.
Described as a collective focused on data exfiltration rather than encryption, mentioned in the context of Conti members splintering into other groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.