BazarLoader, also referred to as Baza and sometimes BazarBackdoor, is a Windows malware family associated with the TrickBot cybercrime ecosystem and closely linked to Conti and Ryuk intrusion activity. First identified in 2020, it has been used primarily as an initial-access and payload-delivery malware that establishes a foothold on victim systems and then retrieves or deploys follow-on tooling, most notably Cobalt Strike. It has been repeatedly described as a key enabler in financially motivated intrusions that progress from phishing-based compromise to full domain takeover and ransomware deployment.
BazarLoader has been delivered through targeted phishing and spearphishing campaigns using lures such as invoices, complaints, or document-themed archives, including ZIP-delivered JavaScript chains. It has also been distributed through malicious Windows App Installer packages masquerading as legitimate software components. Campaign reporting ties it to socially engineered landing pages and email-driven infection flows aimed at high-value organizations.
Operationally, BazarLoader functions as a loader or backdoor-style access malware that downloads additional payloads onto compromised hosts and provides remote access for subsequent attacker activity. Across multiple observed intrusions, BazarLoader infections were followed by Cobalt Strike deployment, after which operators conducted reconnaissance, credential theft, lateral movement, persistence, and broader network compromise. It has been repeatedly associated with ransomware operations in which access obtained through BazarLoader was later used to deploy Ryuk or Conti. Reporting also links it to healthcare-targeted attacks and other enterprise intrusions where rapid escalation from initial compromise to domain-wide impact was observed.
The malware family has also been discussed in relation to a domain generation algorithm used in some variants and to infrastructure patterns overlapping with other TrickBot-linked operations. Security reporting and leaked criminal communications have tied BazarLoader distribution and administration to actors within the broader TrickBot and Conti ecosystem, including groups tracked as GOLD BLACKBURN, GOLD ULRICK, and ITG23. Overall, BazarLoader is best understood as a stealth-oriented Windows loader central to initial access brokerage and follow-on ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers.
External User Tags #bazarloader
Update (2021-01-15): Microsoft Security Response has issued CVE-2021-43890 in reference to the vulnerability in the App installer process described below. The bug was fixed in the January, 2022 Patch Tuesday release.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
top-tier cybercriminal groups, like Conti (loaded by TrickBot and BazarLoader) and DoppelPaymer (loaded by Dridex) were left without a viable option for high-quality initial access.
Previously, the crypters were used predominately with the core malware families associated with ITG23 and their close partners; this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike...
Members of the Trickbot gang are long time partners of Conti, and they have recently developed BazarLoader which downloads additional malware onto a victim’s computer.
B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot... Since then, the terms Baza or Bazarloader have been used interchangeably to reference this particular malware family.
BazarLoader (also known as Bazar Loader, Bazar Backdoor or Team9 Backdoor) is a module of the dreaded TrickBot Trojan. It is mostly used to gain a foothold in compromised enterprise networks.
the Conti operators may have gone for using both Emotet and BazarLoader to access their victim’s networks
29 distinct techniques documented for this family, organized by ATT&CK tactic.
In the majority of the intrusions, the malware was distributed in the form of non-targeted phishing, such as mass malware spam campaigns.
The most common initial infection vectors used are spear phishing and RDP (Remote Desktop Protocol) services. Phishing emails work either through malicious attachments, such as Word documents with an embedded macro that can be used to drop/download BazarLoader, Trickbot, IceID trojans
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The command table allows to handshake, heartbeat, shellcode, powershell or cmd, as evidenced in the strings seen during execution.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... The group used malicious spam that contains a password-protected Word document with malicious macros.
The downloaded file is an executable that will install the BazarLoader infection onto a victim's computer when executed.
there is an Excel spreadsheet named subscription_1617056233.xlsb . This spreadsheet has malicious macros. | At the video's 10 minute mark, I enable macros on the malicious spreadsheet, but nothing apparently happened. So the call center operator had me re-open the spreadsheet and enable macros again.
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The second is opaque predicate, a technique used for control flow obfuscation... Malware authors make use of multiple OPs together with unexecuted code blocks to add complexities that static analysis tools have to deal with. | The first technique is API function hashing, a known trick to obfuscate which functions are called... BazarLoader obfuscates its function calls to make analysis more difficult and to evade detection techniques that rely on reading the IAT.
In fact, BazarLoader resolves every API function to be called individually at run time... The API function resolution procedure ... returns the address of the requested function.
an Excel document that is made to look like a regular form, but it’s actually a malware-embedded file... The use of phone calls and the BazarCall operators’ adoption of a regular company identity has had victims convinced of the bogus service and subscription.
The sample will finally inject the following executable, which only 3 out of 76 products even classify as malicious.
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
After gaining access to a Windows domain controller, the attackers then deploy the Ryuk ransomware on the network to encrypt all of its devices...
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
Cobalt Strike was sent through encrypted HTTPS traffic generated by BazaLoader.
Many of these servers have also acted as Cobalt Strike beacon C2 servers.
That second time, the campo URL redirected to: hxxp://veso2[.]xyz/uploads/files/rt3ret3.exe The above URL returned a Windows executable (EXE) file.
When installed, BazarLoader will eventually deploy Cobalt Strike, which allows threat actors to remotely access the victim's computer and use it to compromise the rest of the network.
266 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family distributed via similar infection chains and as a comparison point for tracking C2 infrastructure.
Additional malware deployed by the TrickBot ecosystem in related campaigns.
Loader family referenced as part of tracked C2 infrastructure in Abuse.ch Feodo Tracker.
Loader malware mentioned as associated with TrickBot in the broader Conti malware ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.