BazarBackdoor is a Windows backdoor associated with the TrickBot ecosystem and later closely tied to Conti-linked intrusion operations. It emerged around 2020 as a common payload delivered by BazarLoader and evolved into a stealthier access malware used to obtain and maintain remote access to enterprise environments, often as a precursor to ransomware deployment. Security reporting frequently links its development and operational use to the same criminal cluster tracked as TrickBot, Wizard Spider, or ITG23.
BazarBackdoor is used primarily for covert remote access and follow-on intrusion enablement. Reported behavior includes command-and-control communications over encrypted channels, fileless or low-footprint execution, payload retrieval, and code injection into legitimate Windows processes. Observed execution chains include process hollowing and process doppelgänging, with payloads injected into trusted system processes to reduce visibility. Persistence has been established through scheduled tasks that relaunch the loader or refresh the backdoor at user logon, enabling operators to update tooling and sustain access.
The malware is commonly delivered through phishing-driven infection chains. Document-themed and business-themed lures have included customer complaints, payroll reports, termination notices, payment remittance messages, and similar social-engineering pretexts. Delivery mechanisms observed in campaigns include links to landing pages, disguised executables masquerading as documents, malicious spreadsheet or document macros, password-protected archives, JavaScript or HTA downloaders, and abuse of Excel DDE behavior. In many cases BazarLoader installs or retrieves BazarBackdoor as the next-stage payload.
Operationally, BazarBackdoor has been used to gain access to corporate networks that are then assessed for value and exploited further with reconnaissance, credential theft, lateral movement, Cobalt Strike deployment, and ultimately ransomware such as Ryuk or Conti. Reporting also describes its role as an access tool for high-value enterprise targets and as part of broader post-compromise workflows involving Active Directory enumeration and domain-wide compromise. Its use has been repeatedly associated with financially motivated campaigns targeting organizations across multiple sectors, including enterprise and healthcare environments.
BazarBackdoor is also notable for infrastructure and communications tradecraft linked to the broader Baza ecosystem, including use of decentralized or alternative DNS mechanisms in some campaigns and domain-generation approaches documented by researchers. Across public reporting, the malware is consistently characterized as a stealth-focused Windows backdoor central to the transition from TrickBot-era banking malware operations toward modern ransomware-oriented initial access and intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Update (2021-01-15): Microsoft Security Response has issued CVE-2021-43890 in reference to the vulnerability in the App installer process described below. The bug was fixed in the January, 2022 Patch Tuesday release. | The payloads, belonging to a malware family variously known as BazarBackdoor and BazarLoader, were delivered by abusing a novel mechanism... The malware that eventually was installed is BazarBackdoor.
"Privileges have been escalated using Mimikatz, Rubeus4 [13], or by exploiting a Zerologon vulnerability (CVE-2020-1472) [26]."
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot by multiple security vendors over the past year.
The TrickBot Gang is most known for its namesake, the TrickBot banking trojan, but is also behind the development of the BazarBackdoor and Anchor backdoors.
According to a separate report published by Advanced Intelligence (AdvIntel) last week, the Conti ransomware cartel is believed to have acqui-hired several elite developers of TrickBot to retire the malware and switch to upgraded variants such as BazarBackdoor.
In October 2021, the IBM X-Force reported that the threat group ITG23 ... had partnered with Shathak ... to distribute the TrickBot and the BazarBackdoor (also referred to as BazarLoader) malware.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Initially appearing around April of 2020, the malware was spread in email campaigns utilizing infrastructure previously used to distribute Trickbot.
This =WmiC| command is a DDE function that causes Microsoft Excel, if given permission, to launch WMIC.exe and execute the provided PowerShell command to input data into the open workbook.
This sets a scheduled task that launches the loader every time the user logs into Windows, which makes way for new versions of the backdoor to be downloaded and injected into svchost.exe.
In this particular case, the DDE will use WMIC to create a new PowerShell process that opens a remote URL containing another PowerShell command that is then executed.
The shortcut file has to be run by the victim to begin the chain of infection.
Microsoft Excel supports a feature called Dynamic Data Exchange (DDE), which can be used to execute commands whose output is inputted into the open spreadsheet, including CSV files. Unfortunately, threat actors can also abuse this feature to execute commands that download and install malware on unsuspecting victims.
This sets a scheduled task that launches the loader every time the user logs into Windows, which makes way for new versions of the backdoor to be downloaded and injected into svchost.exe.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
One of those methods is string obfuscation, where the malware uses encoded stack strings to hide them from static analysis.
At this point, we can safely guess that sub_1800045D6 is an API resolving function, and the parameter it takes is the hash of the API’s name.
Clicking on the link downloads an executable that masquerades through icons and names associated with the mentioned file types. For instance, the supposed customer complaint document will be downloaded as Preview.PDF.exe, which uses the PDF icon. Since the file extension is hidden by default, the file will convincingly appear as a PDF file.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
The payload will then be injected filelessly into C:\Windows\system32\svchost.exe through process hollowing and process doppelgänging techniques.
a typical encoded string is pushed on the stack and decoded dynamically using some multiplication, subtraction, and modulus operations.
The macro drops a Microsoft Hypertext Markup Language (HTML) Applications (HTA) file on the file system and then executes the file using the mshta.exe Windows utility.
downloads a file and writes it to disk as a .jpg file and registers it as a service using regsrv32.exe.
Then, it just executes qmemcpy to copy the data in the second variable to the returned virtual base address. This tells us two things. First, our guess that the v19 variable will contain the address to executable code is correct. Second, we know that the executable code is shellcode since the data is mapped and executed directly at offset 0 from where it is written.
net view /all /domain Enumerates all shared computers and resources on the system and all domains in the network.
After launching the file, the loader sleeps for some time, then connects to command and control (C&C) servers to check-in and download the payload.
retrieving BazarBackdoor using HTTPS traffic from 104.248.174[.]225 over TCP port 443. Then BazarBackdoor generated C2 activity using HTTPS traffic
Then the BazarLoader will download and install the BazarBackdoor.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A backdoor/loader delivered via malicious App Installer packages that injects into a headless msedge.exe process, beacons to command-and-control over HTTPS using cookie and Set-Cookie headers, and performs host and network profiling via PowerShell and native Windows commands.
A backdoor malware family referenced as one of the malware projects worked on by a Conti subteam.
Backdoor malware operation referenced as being under Conti syndicate control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.