Researchers documented multiple BazaLoader campaigns that used high-interaction phishing lures, including Valentine’s Day retail themes and DocuSign-themed spreadsheets, to trick users into visiting spoofed sites, downloading malicious Excel files, and enabling macros. Once executed, the malware established persistence, injected into legitimate processes, contacted command-and-control infrastructure, and used evolving techniques such as updated .bazar domain-generation logic and heavily obfuscated strings to hinder detection and analysis.
Incident reports showed BazaLoader frequently serving as an initial access loader for broader intrusions that quickly escalated to Cobalt Strike, AdFind reconnaissance, credential theft, lateral movement, and in some cases Anchor DNS deployment, behavior widely associated with Ryuk and later Conti ransomware operations. In one case, reconnaissance began within 41 minutes of infection; in another, attackers progressed from a single endpoint to domain controller access over five days, reinforcing assessments that BazaLoader was a key entry point in enterprise ransomware playbooks tied to TrickBot-aligned affiliates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
23 events from the most recent confirmed update back to the earliest known activity.
Malware-Traffic-Analysis.net documented a BazarLoader infection observed on 2022-02-07 that also involved Cobalt Strike. The page provided downloadable indicators of compromise, a packet capture, and malware artifacts for the infection chain.
A phishing campaign observed by researcher Chris Campbell used 'Payment Remittance Advice' emails linking to malicious CSV files that abused Microsoft Excel's Dynamic Data Exchange prompts to launch WMIC and PowerShell, download a DLL, and install BazarLoader leading to BazarBackdoor. AdvIntel's Vitali Kremez said telemetry showed 102 real corporate and government victims over the prior two days.
About 41 minutes after the August 19, 2021 BazarLoader infection, the host began generating Cobalt Strike traffic, and roughly two minutes later AdFind appeared to enumerate the Active Directory environment. Unit 42 noted no ransomware was deployed because the environment was not considered a high-value target.
Unit 42 analyzed an infection generated on August 19, 2021 in which a malicious Excel spreadsheet downloaded a BazarLoader DLL from pawevi[.]com and established command-and-control activity. The DLL was executed with regsvr32.exe and persisted via a registry update.
Unit 42 said the malicious .xlsb spreadsheet used in its case study was discovered on August 18, 2021 and had a last modified date of August 17, 2021. The file used DocuSign branding and macros to deliver BazarLoader.
Malware-Traffic-Analysis.net documented an infection observed on 2021-08-12 in which a ZIP archive named 'Stolen Images Evidence.zip' delivered BazarLoader, followed by Cobalt Strike activity. The case included associated IOCs, packet capture data, and malware samples such as 'Stolen Images Evidence.js' and 'VieFT.dat.'
Unit 42 documented a BazarCall social-engineering infection on April 14, 2021 in which a fake subscription-cancellation email led a victim to call a phone number, visit a fake website, download an Excel file, and enable macros that installed BazarLoader. The report tied the infection to Campo Loader redirect URLs, BazarLoader download URLs, and host artifacts created under C:\Users\Public and C:\ProgramData.
FortiGuard Labs reported a new Bazar Trojan variant spread via phishing emails that redirected victims to fake document downloads such as Preview_report20-01.exe. The analysis detailed its SSL C2 communications with englewoodcarwashh[.]us:443, Date-header-based client verification, and injection of the decrypted payload into cmd.exe.
Proofpoint published analysis on February 11, 2021 describing January and February BazaLoader phishing campaigns that required unusually high user interaction. The company assessed these campaigns were not associated with TA800 or TA572 and likely involved other affiliates.
Proofpoint reported additional BazaLoader payload URLs, hashes, and C2 infrastructure first observed on February 8, 2021. The indicators included both conventional domains and .bazar-based command-and-control infrastructure.
Proofpoint listed another set of BazaLoader payload and command-and-control indicators first observed on February 1, 2021. These included a new payload URL, malware hash, and several HTTPS C2 URLs.
Proofpoint reported BazaLoader payload URLs, hashes, and command-and-control URLs first observed on January 29, 2021, tied to one of the phishing campaigns. The indicators included an Excel payload URL and multiple HTTPS C2 endpoints.
The same January 2021 Bazar Loader sample was first detected on VirusTotal on January 23, 2021, followed later that day by detections of its unpacked second stage and final payload.
A Johannes Bader analysis documented a Bazar Loader sample named Preview_report20-01.exe compiled on January 20, 2021, reflecting a slight update to the malware's domain generation algorithm compared with the December version.
Unit 42 reported that multiple campaigns distributed BazarLoader during summer 2021. From late July through mid-August 2021, three major campaigns were BazarCall, a copyright-violation themed campaign, and TA551 (Shathak).
Proofpoint observed several BazaLoader phishing campaigns in January 2021 using Valentine's Day themes such as flowers and lingerie. These campaigns relied on fake retail websites, PDF order lures, and Excel macros to deliver the malware.
Hornetsecurity said it first observed a BazarLoader phishing campaign on 2020-10-13 at 13:00 UTC using fake termination-themed emails and a legitimate Google Docs link to deliver a malware executable named Report10-13.exe. The report said the loader used OpenNIC DNS and a DGA-generated .bazar domain tied to EmerDNS to fetch BazarBackdoor, with Ryuk ransomware as the eventual monetization stage.
Proofpoint stated that BazaLoader was first observed in the wild in April 2020. Later analysis pieces also referenced April 2020 as the malware family's initial discovery period.
Proofpoint reported that BazaLoader campaign volume increased during 2020 and peaked in October. It also correlated some 2020 BazaLoader campaigns with public reports of affiliate activity associated with Ryuk ransomware infections.
A forensic analysis documented a BazarISO sample distributed as an ISO file named Documents-17.iso containing docs.lnk and autorun.exe. The LNK launched rundll32.exe with advpack.dll,RegisterOCX to execute the payload, and static analysis indicated capabilities including keylogging, registry modification, file discovery, and anti-debugging behavior.
The DFIR Report said the Bazar, Cobalt Strike, and Anchor DNS intrusion progressed from a single endpoint to full domain compromise within five days. During that period, the attackers performed credential dumping, lateral movement, and extensive network discovery.
In the same intrusion, Bazar established persistence and reconnaissance, then about one hour later launched Cobalt Strike, after which Anchor DNS was dropped and executed. The report assessed the activity as consistent with pre-ransomware operations associated with Ryuk-linked actors.
The DFIR Report described an intrusion beginning with a malicious DocuSign-themed Excel 4.0 macro document that retrieved a payload from morrislibraryconsulting[.]com. The follow-on malware was manually executed as a Bazar loader sample.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
isc.sans.edu
Open sourceisc.sans.edu
Open sourcemalware-traffic-analysis.net
Open sourcemalware-traffic-analysis.net
Open sourcefortinet.com
Open sourceproofpoint.com
Open sourcefireeye.com
Open sourcehornetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.