BazarBackdoor is a Windows backdoor developed by the TrickBot cybercrime group, also tracked as ITG23 and Wizard Spider. First identified alongside BazarLoader in April 2020, it provides covert remote access to compromised corporate networks and supports follow-on malware deployment. BazarLoader is the delivery component that downloads and installs the backdoor, although the two names have sometimes been used interchangeably. BazarBackdoor has been used in Ryuk and Conti ransomware intrusion chains, including attacks against healthcare organizations, and has also affected corporate and government victims.
Distribution commonly begins with phishing emails using employment termination, payroll, customer complaint, or payment-remittance lures. Infection chains include links to document-themed landing pages that deliver disguised executables, macro-enabled documents inside password-protected archives, and malicious CSV files that abuse Microsoft Excel's Dynamic Data Exchange functionality. TA551, also known as Shathak, has distributed BazarBackdoor in partnership with ITG23.
Observed execution chains inject the backdoor into a legitimate Windows service-host process using process hollowing and process doppelgänging, enabling fileless payload execution. Scheduled tasks provide persistence by relaunching the loader at user logon, allowing the backdoor to be downloaded and injected again. Command-and-control mechanisms include HTTPS communications, domain generation algorithms, and decentralized Emercoin DNS resolution. Attackers use the resulting access to support lateral movement and deploy additional tooling such as Cobalt Strike before ransomware execution. Conti adopted BazarBackdoor as a stealthier initial-access alternative to TrickBot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Update (2021-01-15): Microsoft Security Response has issued CVE-2021-43890 in reference to the vulnerability in the App installer process described below. The bug was fixed in the January, 2022 Patch Tuesday release. | The payloads, belonging to a malware family variously known as BazarBackdoor and BazarLoader, were delivered by abusing a novel mechanism... The malware that eventually was installed is BazarBackdoor.
"Privileges have been escalated using Mimikatz, Rubeus4 [13], or by exploiting a Zerologon vulnerability (CVE-2020-1472) [26]."
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, the Conti group has exhibited notable ambition with technical impact enhancements by way of Trickbot, as well as plans to use the “BazarBackdoor” malware to improve access points, and persistence.
B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot by multiple security vendors over the past year.
The TrickBot Gang is most known for its namesake, the TrickBot banking trojan, but is also behind the development of the BazarBackdoor and Anchor backdoors.
In October 2021, the IBM X-Force reported that the threat group ITG23 ... had partnered with Shathak ... to distribute the TrickBot and the BazarBackdoor (also referred to as BazarLoader) malware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Initially appearing around April of 2020, the malware was spread in email campaigns utilizing infrastructure previously used to distribute Trickbot.
This =WmiC| command is a DDE function that causes Microsoft Excel, if given permission, to launch WMIC.exe and execute the provided PowerShell command to input data into the open workbook.
This sets a scheduled task that launches the loader every time the user logs into Windows, which makes way for new versions of the backdoor to be downloaded and injected into svchost.exe.
In this particular case, the DDE will use WMIC to create a new PowerShell process that opens a remote URL containing another PowerShell command that is then executed.
The shortcut file has to be run by the victim to begin the chain of infection.
Microsoft Excel supports a feature called Dynamic Data Exchange (DDE), which can be used to execute commands whose output is inputted into the open spreadsheet, including CSV files. Unfortunately, threat actors can also abuse this feature to execute commands that download and install malware on unsuspecting victims.
This sets a scheduled task that launches the loader every time the user logs into Windows, which makes way for new versions of the backdoor to be downloaded and injected into svchost.exe.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
One of those methods is string obfuscation, where the malware uses encoded stack strings to hide them from static analysis.
At this point, we can safely guess that sub_1800045D6 is an API resolving function, and the parameter it takes is the hash of the API’s name.
Clicking on the link downloads an executable that masquerades through icons and names associated with the mentioned file types. For instance, the supposed customer complaint document will be downloaded as Preview.PDF.exe, which uses the PDF icon. Since the file extension is hidden by default, the file will convincingly appear as a PDF file.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
a typical encoded string is pushed on the stack and decoded dynamically using some multiplication, subtraction, and modulus operations.
The macro drops a Microsoft Hypertext Markup Language (HTML) Applications (HTA) file on the file system and then executes the file using the mshta.exe Windows utility.
downloads a file and writes it to disk as a .jpg file and registers it as a service using regsrv32.exe.
Then, it just executes qmemcpy to copy the data in the second variable to the returned virtual base address. This tells us two things. First, our guess that the v19 variable will contain the address to executable code is correct. Second, we know that the executable code is shellcode since the data is mapped and executed directly at offset 0 from where it is written.
net view /all /domain Enumerates all shared computers and resources on the system and all domains in the network.
After launching the file, the loader sleeps for some time, then connects to command and control (C&C) servers to check-in and download the payload.
retrieving BazarBackdoor using HTTPS traffic from 104.248.174[.]225 over TCP port 443. Then BazarBackdoor generated C2 activity using HTTPS traffic
Then the BazarLoader will download and install the BazarBackdoor.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A backdoor/loader delivered via malicious App Installer packages that injects into a headless msedge.exe process, beacons to command-and-control over HTTPS using cookie and Set-Cookie headers, and performs host and network profiling via PowerShell and native Windows commands.
A backdoor malware family referenced as one of the malware projects worked on by a Conti subteam.
Backdoor malware operation referenced as being under Conti syndicate control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.