Bazar is a Windows backdoor malware family with development ties to the TrickBot group and documented use by Wizard Spider. Also tracked under names including BazaLoader, KEGTAP, and Team9, it establishes footholds in high-value targets and downloads and executes additional payloads. These include Cobalt Strike, IcedID, TrickBot, and Emotet. Bazar supports multi-stage intrusions and has been associated with ransomware delivery chains.
Distribution methods include phishing emails containing malicious links and spearphishing attachments, including macro-enabled Microsoft Office documents and PDFs containing download links. After compromise, Bazar can execute PowerShell scripts received from command-and-control infrastructure. Its reconnaissance capabilities include identifying the current process and infected user, collecting the host's IP address, NetBIOS name, and system time, and enumerating remote systems and shared drives within a domain. It establishes persistence through scheduled tasks and registry-based autostart mechanisms. Bazar also supports process injection, including use of VirtualAllocExNuma and process hollowing, allowing malicious code to execute within legitimate Windows processes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the seller offered two types of weaponized Microsoft Office documents (maldocs) to users: one that exploits a known vulnerability in Microsoft Office (CVE-2017-8570) and another that uses a malicious macro.
Additionally, some of the infrastructure that hosted the oleObjects utilized in the August 2021 attacks abusing CVE-2021-40444 were also involved in the delivery of BazaLoader and Trickbot payloads — activity that overlaps with a group Microsoft tracks as DEV-0193. | In August, Microsoft Threat Intelligence Center (MSTIC) identified a small number of attacks (less than 10) that attempted to exploit a remote code execution vulnerability in MSHTML using specially crafted Microsoft Office documents. These attacks used the vulnerability, tracked as CVE-2021-40444, as part of an initial access campaign that distributed custom Cobalt Strike Beacon loaders.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.
This actor has predominantly used BazaLoader since April of 2020, but on February 3rd, 2021 they distributed a new malware we are calling NimzaLoader... there has been some research community analysis suggesting that NimzaLoader is just another variant of BazaLoader, but based on our observations of significant differences, we are tracking this as a distinct malware family.
Domains serving Bazar loader files ... Bazar domains ... Operational Backdoor
Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
BazaLoader is a downloader written in C++ whose primary function is to download and execute additional modules. It was first observed in the wild in April 2020 and since has steadily been adopted by more actors.
TA578 uses email campaigns to deliver malware like Ursnif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader, as well as Cobalt Strike.
49 distinct techniques documented for this family, organized by ATT&CK tactic.
250 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
157 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bazar is a backdoor used by Conti to gain access to targets; the article says it was formerly part of TrickBot and later became a stand-alone tool used against higher-value targets.
A malware/tooling family mentioned in passing as connected with Cobalt Strike and TrickBot.
Bazar is referenced as a loader used in the same Ryuk campaign to gain initial access before follow-on tooling such as SystemBC and ransomware deployment.
A loader/backdoor payload delivered by EtterSilent maldocs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.