BazarLoader is a Windows malware loader used to establish an initial foothold and deliver follow-on payloads, including BazarBackdoor and, in many intrusions, post-exploitation frameworks and ransomware-enabling tooling. It has been closely associated with the TrickBot and Conti ecosystems and has been used by clusters and operations tracked as TA551, UNC2053, FIN12, Wizard Spider-linked activity, and related ransomware intrusion sets. BazarLoader has been repeatedly observed as part of access chains that precede Ryuk and Conti ransomware deployment, as well as broader hands-on-keyboard activity involving reconnaissance, credential theft, lateral movement, and data theft.
Distribution has most commonly relied on phishing-based social engineering. Observed delivery patterns include malicious links or attachments in email campaigns, actor-controlled file-hosting pages, macro-enabled Office documents, HTA and script-based infection chains, and the call-center-assisted BazarCall scheme in which victims are socially engineered into downloading and enabling malicious documents. TA551 campaigns have also delivered BazarLoader through malspam using password-protected archives, malicious Word documents, embedded HTA content, obfuscated scripts, and staged payload retrieval.
Functionally, BazarLoader serves as a loader/downloader that retrieves and executes additional malware from command-and-control infrastructure. Public reporting has described close operational coupling between BazarLoader and BazarBackdoor, including shared infrastructure and chained delivery behavior. In enterprise intrusions, BazarLoader infections have provided remote access that operators later used for reconnaissance, Active Directory enumeration, credential access, lateral movement, and eventual ransomware deployment. It has therefore played a recurring role as an initial-access and post-compromise enabler rather than as the final monetization payload itself.
BazarLoader is also notable for its use of domain generation algorithms in some variants. Reverse engineering has documented multiple DGA implementations and implementation flaws, including variants that generated invalid domains because of coding errors and others that used the .bazar naming scheme with date-dependent deterministic generation. These analyses indicate active development and iterative changes by the operators.
Victimology has skewed toward large enterprise environments, with repeated use against healthcare and other high-value corporate targets in North America and elsewhere. In ransomware operations linked to FIN12 and Conti-aligned activity, BazarLoader has been part of fast-moving intrusion playbooks that prioritize rapid transition from initial access to widespread compromise and ransomware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
External User Tags #bazarloader
Update (2021-01-15): Microsoft Security Response has issued CVE-2021-43890 in reference to the vulnerability in the App installer process described below. The bug was fixed in the January, 2022 Patch Tuesday release.
"Privileges have been escalated using Mimikatz, Rubeus4 [13], or by exploiting a Zerologon vulnerability (CVE-2020-1472) [26]."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This attack chain has also been utilized from threat actors InSideCopy, TA551 and from BazarLoader campaigns.
This attack chain has also been utilized from threat actors InSideCopy, TA551 and from BazarLoader campaigns.
The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT.
After a break in FIN12 activity from late March 2020 to late August 2020, FIN12 resumed operations shifting their reliance for initial access away from TRICKBOT to BAZARLOADER malware in September 2020.
When the BazarCall campaign first started, it was used to distribute the BazarLoader malware but has also begun distributing TrickBot, IcedID, Gozi IFSB, and other malware.
Commentaire : les attaquants impliqués dans l’incident du CHU de Brest seraient donc actifs depuis au moins 2019 et auraient utilisé successivement les rançongiciels Ryuk, Conti, Hive, Nokoyawa et Play. Ils auraient également eu recours aux services du code malveillant BazarLoader entre 2020 et 2021.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
In an observed Ryuk campaign (figure 7), a phishing email was used to deliver Bazarloader through a malicious link
The email contains a ZIP attachment which is protected with a password that is provided in the email text. Unzipping the attachment leads to a word document.
Both Javascript files are executed with eval one after the other, so we can merge them into one file...
The word documents contains an hta script, which is hidden by setting it in a white, 1px-sized font. A macro file writes that script to disk and runs it.
The hta script deobfuscates and executes Javascript. The Javascript then downloads and runs the BazarLoader payload from a hard-coded URL using ActiveX.
“They contain links to Google Docs pages of document previews, prompting the victim to download the file… The files concerned are executables signed with revoked certificates…”
When the user enters their customer ID number, the website will automatically prompt the browser to download an Excel document (xls or xlsb). The call center agent will then help the victim open the file and clicking on the 'Enable Content' button to enable malicious macros.
“Bazar activity can be identified by searching the system startup folders and Userinit values under… Winlogon registry key: %APPDATA%\…\Startup\adobe.lnk” / (Ryuk table) “Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder… create a Registry entry…\Run to establish persistence.”
“Bazar activity can be identified by searching the system startup folders and Userinit values under… Winlogon registry key: %APPDATA%\…\Startup\adobe.lnk” / (Ryuk table) “Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder… create a Registry entry…\Run to establish persistence.”
the attacker simply added individual display properties for the program’s name (“Adobe PDF Component”), publisher (“Adobe Inc.”), and an Adobe Acrobat logo graphic stored in a subfolder.
The random number generator is finally used to generate the domain names ... In total, 100 domains are generated.
Like many other malware, BazarBackdoor (and its related sibling BazarLoader) communicates over HTTPS
The Javascript then downloads and runs the BazarLoader payload from a hard-coded URL using ActiveX.
the malware uses “cookies” in the HTTPS GET or POST headers to transmit information to the server, and receives commands from the C2 in the form of one or more “Set-Cookie” response headers.
The gang seems to focus on high-profile corporate networks, which they compromise by targeting critical devices with BazarLoader or TrickBot malware to gain unauthorized remote access.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader family referenced as part of tracked C2 infrastructure in Abuse.ch Feodo Tracker.
Loader malware mentioned as associated with TrickBot in the broader Conti malware ecosystem.
A named loader/dropper listed in the RAMP malware marketplace.
BazarLoader is a loader malware known for using application sideloading techniques, such as leveraging AppX packages staged in common user directories, to gain initial access and deploy additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.