Proofpoint reported that threat actor TA800 used personalized phishing emails to deliver a newly identified loader dubbed NimzaLoader, while separate analysis referred to the malware as NimarLoader or Nimrod. The campaign sent recipients to GetResponse landing pages and then to a fake PDF executable hosted on Slack, after which the malware established HTTPS command-and-control using encrypted JSON messages and a key-exchange routine. Researchers said the loader was written in the Nim programming language, used encrypted or XOR-decoded strings, and included functionality for handshake, heartbeat, cmd, powershell, and shellcode execution.
Both analyses concluded the malware had been initially confused with BazaLoader/BazarLoader because of overlapping campaign traits and infrastructure, but they found it to be a separate malware family with a different codebase and implementation. Observed activity included fileless delivery of Cobalt Strike stagers, and one campaign contacted topservicebin[.]com, which resolved to 45.141.87.41; researchers also noted SSL certificate similarities with infrastructure tied to other Cobalt Strike deployments associated with BazarLoader and Ryuk. The reporting indicates TA800 introduced a new initial-access tool that may share operational infrastructure patterns with existing criminal ecosystems without being the same malware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Proofpoint published analysis on March 9, 2021 of TA800's February 3 campaign, naming the malware NimzaLoader and assessing it was not a BazaLoader variant. The company detailed its Nim-based implementation, encrypted strings, HTTPS JSON C2 design, and phishing delivery via GetResponse pages and Slack-hosted fake PDF executables.
On March 1, 2021, Joshua Platt and Jason Reaves of Walmart published an analysis of the malware under the name NimarLoader, also called Nimrod. They argued it was distinct from the Baza family despite overlapping campaign traits and infrastructure patterns.
Proofpoint found the analyzed NimzaLoader sample contained an encrypted Unix epoch expiration timestamp and was configured to stop running after February 10, 2021 at 13:20:55.003 GMT. This reflects a built-in execution cutoff in the malware sample.
On February 3, 2021, Walmart researchers detected campaigns previously attributed to Baza that used different request headers and concluded the malware was something new. Proofpoint also observed a TA800 email campaign on the same date distributing the newly identified loader.
Proofpoint said TA800 had predominantly used BazaLoader since April 2020 before later distributing NimzaLoader. Walmart's analysis also noted Baza/BazarLoader first appeared around April 2020.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourcemedium.com
Open sourcemedium.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.