Researchers detailed how BazarLoader evolved as an enterprise-focused malware loader tied to the TrickBot ecosystem, using the decentralized .bazar namespace on EmerDNS/OpenNIC for command-and-control and rotating algorithmically generated domains each month. Early variants generated 12-character domains and later shifted to 8-character patterns built from consonant-vowel pairs, expanding the monthly candidate pool from about 2,160 to 12,996 domains; one later variant contained a coding flaw that caused many summer-month domains to become invalid, disrupting parts of its own DGA-based infrastructure.
Separate reverse-engineering of BazarLoader’s infection chain showed the malware commonly arrived through phishing and malicious ISO files, where an LNK launched a DLL via rundll32.exe, unpacked shellcode, and exposed the final loader. The loader used anti-analysis checks, language-based execution filtering, dynamic API resolution, decoy traffic, cryptographic validation, and process hollowing, then fetched follow-on payloads from hard-coded HTTPS IPs or fallback .bazar domains to deliver tools such as Cobalt Strike and Conti ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
A May 2022 analysis documented BazarLoader's final-stage behavior, including anti-analysis checks, decoy web traffic, RSA/SHA384-based payload handling, and fallback to OpenNIC DNS if hard-coded HTTPS IP C2s failed. The sample resolved .bazar domains including reddew28c.bazar, bluehail.bazar, and whitestorm9p.bazar before injecting payloads via process hollowing.
An April 2022 reverse-engineering write-up described a BazarLoader delivery chain in which phishing emails led victims to download an ISO file, mount it, and execute Attachments.lnk, which launched documents.log via rundll32.exe. The analysis traced unpacking through shellcode to the final BazarLoader payload and documented its anti-analysis techniques.
A BazarLoader sample later found to contain a faulty hard-coded permutation in its DGA was compiled on 2021-07-13, with the unpacked sample compiled on 2021-07-12. The bug caused invalid .bazar domain generation during summer months, especially July through September.
Research published in July 2021 showed that a non-bijective 228-byte permutation array left many domain-generation positions undefined. As a result, June domains were partly broken and July through September domains were mostly invalid, while October through May worked as intended.
An analyzed packed Bazar Loader sample tied to the new DGA was compiled on 2020-12-10, with its unpacked payload compiled on 2020-12-09. The sample used dynamic API loading, encrypted strings, and arithmetic-identity obfuscation also noted in Zloader.
A new Bazar Loader DGA version appeared in December 2020 that still used the .bazar TLD but switched from 12-character to 8-character second-level domains. The revised algorithm generated domains from consonant-vowel character pairs and was capable of producing 12,996 possible domains per month.
A Cybereason report dated 2020-07-13 cataloged SHA-256 hashes spanning Team9/Bazar operational loaders, development backdoor versions, and operational backdoors. It also disclosed loader-serving domains, a serving IP, and multiple .bazar domains with associated IP infrastructure tied to the Bazar ecosystem.
VirusTotal detections recorded on 2020-07-10 showed limited coverage for the analyzed BazarLoader chain: 23/76 for the initial sample, 10/75 for the unpacked second stage, and 3/76 for the injected executable. Microsoft and Rising classified the initial sample as TrickBot-related malware.
Analysis published in July 2020 described how BazarLoader generated .bazar domains from constrained character sets and a seed derived from the current month and year. The write-up also noted five attacker-registered DGA domains tied to an Emercoin address and explained how XOR-decrypted DNS A records revealed the real C2 IP.
A BazarLoader sample compiled on 2020-06-17 used a defective DGA that generated invalid domains ending in '.bazaar' and sometimes included illegal special characters in the second-level label. Later analysis attributed the flaw to signed-integer handling in random values produced via BCryptGenRandom, which broke domain generation and greatly expanded the monthly domain space.
A BazarLoader sample associated with TrickBot was compiled on 2020-06-12 and used a domain generation algorithm that produced 12-character .bazar command-and-control domains. Older samples had used hard-coded .bazar domains before this newer DGA-driven behavior.
A Fox-IT report published in June 2020 analyzed the Team9 malware family, also known as Bazar, and assessed that it was being developed by the group behind TrickBot. The write-up detailed early and later loader variants, the Team9 backdoor’s capabilities, and associated .bazar command-and-control infrastructure.
VirusTotal detected the packed sample at 8/72 on 2020-12-11 and the unpacked payload at 4/75 on 2020-12-15. Vendor labels included Win64/Bazar.Y, Backdoor.Win32.Bazdor.co, and Trojan.Win64.BAZALOADER.SMYAAJ-A.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
0ffset.net
Open source0ffset.net
Open sourcejohannesbader.ch
Open sourcejohannesbader.ch
Open sourcejohannesbader.ch
Open sourcejohannesbader.ch
Open sourceblog.fox-it.com
Open sourcecybereason.com
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.