BazarLoader, also known as Baza and sometimes BazarBackdoor, is a Windows malware family associated with the TrickBot and Conti-linked cybercrime ecosystem, including activity tracked as ITG23 and GOLD BLACKBURN. First identified in 2020, it is primarily used as an initial-access malware loader and backdoor that establishes remote access on victim systems and delivers follow-on payloads, most notably Cobalt Strike. It has been repeatedly linked to intrusion chains that culminate in enterprise-wide compromise and ransomware deployment, including Ryuk and Conti operations against high-value targets such as healthcare and other organizations.
BazarLoader has been distributed through targeted phishing and spearphishing campaigns using organization-specific lures such as invoices, complaints, or document-themed decoys, as well as archive-delivered JavaScript chains. It has also been observed delivered through malicious Windows App Installer packages masquerading as legitimate software, using cloud-hosted installation infrastructure. In broader criminal operations, it has functioned as an access-enabling component within a service ecosystem shared across multiple malware families and affiliates.
Operationally, BazarLoader is used to gain footholds, execute additional payloads, and support post-compromise activity by deploying frameworks such as Cobalt Strike. Reporting also ties it to stealthy access in ransomware intrusions, where operators move from the initial infection to credential theft, domain compromise, lateral movement, and rapid ransomware execution. Some analyses describe BazarLoader as the loader component that attempts to retrieve a secondary Bazar backdoor payload. Reverse-engineering has also documented a domain-generation mechanism in at least some variants, including an early flawed implementation associated with EmerDNS-style naming.
BazarLoader is notable less as a standalone commodity implant than as a reliable access mechanism embedded in mature financially motivated intrusion workflows. Its repeated use by Conti- and Ryuk-linked actors, overlap with TrickBot infrastructure and personnel, and frequent pairing with Cobalt Strike make it a significant enabler of large-scale ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In Microsoft’s December 14, 2021, Patch Tuesday vulnerability release, security patches were released for a high severity zero-day vulnerability impacting the Windows AppX installer. The vulnerability is tracked as CVE-2021-43890 (CVSS: 7.1). Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application. Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader. | Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers.
External User Tags #bazarloader
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
top-tier cybercriminal groups, like Conti (loaded by TrickBot and BazarLoader) and DoppelPaymer (loaded by Dridex) were left without a viable option for high-quality initial access.
Previously, the crypters were used predominately with the core malware families associated with ITG23 and their close partners; this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike...
Members of the Trickbot gang are long time partners of Conti, and they have recently developed BazarLoader which downloads additional malware onto a victim’s computer.
B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot... Since then, the terms Baza or Bazarloader have been used interchangeably to reference this particular malware family.
BazarLoader (also known as Bazar Loader, Bazar Backdoor or Team9 Backdoor) is a module of the dreaded TrickBot Trojan. It is mostly used to gain a foothold in compromised enterprise networks.
The emergence of Bumblebee in phishing campaigns in March coincides with a drop in using BazarLoader for delivering file-encrypting malware, researchers say.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
In an attack scenario, threat actors could craft a malicious attachment and deliver it to victims via either email or a link inside of an email; the attachment would appear as a legitimate application.
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The command table allows to handshake, heartbeat, shellcode, powershell or cmd, as evidenced in the strings seen during execution.
The phone operator continues to guide the user into unwittingly enabling macros that will drop a malicious binary... The group used malicious spam that contains a password-protected Word document with malicious macros.
there is an Excel spreadsheet named subscription_1617056233.xlsb . This spreadsheet has malicious macros. | At the video's 10 minute mark, I enable macros on the malicious spreadsheet, but nothing apparently happened. So the call center operator had me re-open the spreadsheet and enable macros again.
After execution of the initial access malware, many threat actors deploy persistence mechanisms, such as the creation of scheduled tasks... Scheduled tasks were the most common persistence method observed in our intrusions.
The second is opaque predicate, a technique used for control flow obfuscation... Malware authors make use of multiple OPs together with unexecuted code blocks to add complexities that static analysis tools have to deal with. | The first technique is API function hashing, a known trick to obfuscate which functions are called... BazarLoader obfuscates its function calls to make analysis more difficult and to evade detection techniques that rely on reading the IAT.
Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application.
The sample will finally inject the following executable, which only 3 out of 76 products even classify as malicious.
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
After gaining access to a Windows domain controller, the attackers then deploy the Ryuk ransomware on the network to encrypt all of its devices...
Malware sometimes abuses these challenges by “sleeping” in the sandbox before carrying out malicious procedures to hide its real intentions. | API Hammering has been a known sandbox bypass technique that is sometimes used by malware authors to evade sandboxes. We’ve recently observed Zloader and the backdoor BazarLoader using new and unique implementations of API Hammering to remain stealthy.
Cobalt Strike was sent through encrypted HTTPS traffic generated by BazaLoader.
Many of these servers have also acted as Cobalt Strike beacon C2 servers.
That second time, the campo URL redirected to: hxxp://veso2[.]xyz/uploads/files/rt3ret3.exe The above URL returned a Windows executable (EXE) file.
When installed, BazarLoader will eventually deploy Cobalt Strike, which allows threat actors to remotely access the victim's computer and use it to compromise the rest of the network.
266 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
113 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another malware family distributed via similar infection chains and as a comparison point for tracking C2 infrastructure.
Additional malware deployed by the TrickBot ecosystem in related campaigns.
Loader family referenced as part of tracked C2 infrastructure in Abuse.ch Feodo Tracker.
Loader malware mentioned as associated with TrickBot in the broader Conti malware ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.