BazarLoader is a Windows malware loader first identified in April 2020 and developed by the TrickBot-linked cybercrime group tracked as ITG23 and Wizard Spider. Its primary function is to download and execute additional malware, providing initial access for subsequent intrusions. Common payloads include BazarBackdoor and Cobalt Strike Beacon. BazarLoader has been a significant enabler of Ryuk and Conti ransomware operations, although ransomware deployment and subsequent network compromise are performed by downstream payloads and operators.
Distribution campaigns use phishing and spearphishing emails with invoice, customer-complaint, retail-order, and purported stolen-image lures. Infection chains have directed recipients to deceptive document-preview pages or delivered ZIP archives containing JavaScript. BazarLoader has also been distributed through malicious Windows App Installer packages hosted on Microsoft Azure. Samples have used abused code-signing certificates and crypters to conceal malicious code and hinder detection. The loader uses a domain generation algorithm and blockchain-based DNS infrastructure to locate payload-delivery infrastructure.
BazarLoader-associated intrusions include UNC1878 campaigns targeting U.S. hospitals and healthcare providers, where the loader delivered Cobalt Strike before attackers compromised Windows domains and deployed Ryuk. Its role in initial-access brokerage and its close operational connections to Conti made it an important component of the ransomware ecosystem during 2020–2022.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In Microsoft’s December 14, 2021, Patch Tuesday vulnerability release, security patches were released for a high severity zero-day vulnerability impacting the Windows AppX installer. The vulnerability is tracked as CVE-2021-43890 (CVSS: 7.1). Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application. Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader. | Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers.
External User Tags #bazarloader
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The reduction in time from broker to ransomware operator is likely due to large-scale BazarLoader and IcedID infection campaigns and broker relationships with the Conti ransomware.
Previously, the crypters were used predominately with the core malware families associated with ITG23 and their close partners; this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike...
Members of the Trickbot gang are long time partners of Conti, and they have recently developed BazarLoader which downloads additional malware onto a victim’s computer.
B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot... Since then, the terms Baza or Bazarloader have been used interchangeably to reference this particular malware family.
BazarLoader (also known as Bazar Loader, Bazar Backdoor or Team9 Backdoor) is a module of the dreaded TrickBot Trojan. It is mostly used to gain a foothold in compromised enterprise networks.
The emergence of Bumblebee in phishing campaigns in March coincides with a drop in using BazarLoader for delivering file-encrypting malware, researchers say.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
In an attack scenario, threat actors could craft a malicious attachment and deliver it to victims via either email or a link inside of an email; the attachment would appear as a legitimate application.
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The command table allows to handshake, heartbeat, shellcode, powershell or cmd, as evidenced in the strings seen during execution.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... The group used malicious spam that contains a password-protected Word document with malicious macros.
there is an Excel spreadsheet named subscription_1617056233.xlsb . This spreadsheet has malicious macros. | At the video's 10 minute mark, I enable macros on the malicious spreadsheet, but nothing apparently happened. So the call center operator had me re-open the spreadsheet and enable macros again.
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The second is opaque predicate, a technique used for control flow obfuscation... Malware authors make use of multiple OPs together with unexecuted code blocks to add complexities that static analysis tools have to deal with. | The first technique is API function hashing, a known trick to obfuscate which functions are called... BazarLoader obfuscates its function calls to make analysis more difficult and to evade detection techniques that rely on reading the IAT.
Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application.
The sample will finally inject the following executable, which only 3 out of 76 products even classify as malicious.
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
After gaining access to a Windows domain controller, the attackers then deploy the Ryuk ransomware on the network to encrypt all of its devices...
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
Cobalt Strike was sent through encrypted HTTPS traffic generated by BazaLoader.
Many of these servers have also acted as Cobalt Strike beacon C2 servers.
That second time, the campo URL redirected to: hxxp://veso2[.]xyz/uploads/files/rt3ret3.exe The above URL returned a Windows executable (EXE) file.
When installed, BazarLoader will eventually deploy Cobalt Strike, which allows threat actors to remotely access the victim's computer and use it to compromise the rest of the network.
266 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
116 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family distributed via similar infection chains and as a comparison point for tracking C2 infrastructure.
Additional malware deployed by the TrickBot ecosystem in related campaigns.
Loader family referenced as part of tracked C2 infrastructure in Abuse.ch Feodo Tracker.
Loader malware mentioned as associated with TrickBot in the broader Conti malware ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.