Bazar

MITRE ATT&CK: S0534 View on attack.mitre.org

Aliases: KEGTAP, Team9, Bazaloader, BEERBOT, Team9Backdoor, bazaloader, bazarloader, Bazar

First seen
2020-04-01 00:00:00
Malware type
backdoor, loader, downloader
Family
Malware family
Operating systems
windows
Related IoCs
178 (134 malicious)
Last IoC activity
2026-09-02 02:42:55
Profile updated
2026-07-07 12:37:50

Targeted industries: professional-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications transportation-and-logistics

Targeted regions: country_code:us country_code:de

Context

Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.

Recent IoC activity

134 malicious indicators in Maltiverse are attributed to Bazar (S0534). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample SharedFiles.dll 2026-08-30 1
file sample Documents.lnk 2026-08-27 1
file sample 0x0005000000012636-65.exe 2026-08-24 1
file sample Insurance_template.rtf 2026-08-24 1
file sample 215e0accdf538d48a8a7bf79009e8f9b.dll 2026-08-01 1
file sample f479a0b3c07a701127b732968a321645.dll 2026-08-01 1
file sample a989a70066d734762a1ec5255604c197.dll 2026-08-01 1
file sample 2026-06-04_6caaeef74d8a3ec9c3c150a114c9d172_amadey_darkgate_elex_emotet_icedi... 2026-07-18 1
file sample sub_8236b4c91e12.bin 2026-07-09 3
file sample JavaObjectReflectiveB.dll 2026-07-09 1
file sample 78991ae2911d410f367535fc91d1c986.dll 2026-06-29 1
file sample docs1549.hta 2026-06-28 1
file sample 3e61dd5bcec1efd3b357c1ca4b8aac54 2026-06-18 1
file sample dr_2557993_.zip 2026-06-16 1
file sample particulars_09.20.2021.doc 2026-06-15 1
file sample 2026-06-01_90d8ff3e5d641f8f1c43879ca00fde27_coinminer_icedid_njrat_remcos 2026-06-01 1
file sample JavaObjectReflectiveW.dll 2026-05-31 1
file sample 1.dll 2026-05-30 1
file sample 85f6edaa9fcf9646a82acef0fdf9873c 2026-05-28 1
file sample bd4953dbce803a724515c75235cd92c0 2026-05-28 1

Detection coverage

  • 5 YARA rules
  • 909 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Domain Account (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Malicious Link (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Process Injection (attack-pattern)
  • BITS Jobs (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • PowerShell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Process Doppelgänging (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Data from Local System (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • System Language Discovery (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Multi-Stage Channels (attack-pattern)
  • Query Registry (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Software Discovery (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_MAL_Bazarloader_Oct_2021_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Bazarloader (yara-rule)
  • DITEKSHEN_MALWARE_Win_UNK05 (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_Bazarloader (yara-rule)
  • CAPE_Bazar (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • CrowdStrike — Report2021Gtr (report)
  • twitter.com — 1321865315513520128 (report)
  • Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
  • blog.google — Exposing Initial Access Broker Ties Conti (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • trellix.com — Evolution Of Bazarcall Social Engineering Tactics (report)
  • Microsoft — Bazacall Phony Call Centers Lead To Exfiltration And Ransomware (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
  • Palo Alto Unit 42 — Luna Moth Callback Phishing (report)
  • securityintelligence.com — Trickbot Gang Doubles Down Enterprise Infection (report)
  • CrowdStrike — Wizard Spider Adversary Update (report)
  • Trend Micro — Rpt Navigating New Frontiers Trend Micro 2021 Annual Cybersecurity Report (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
  • attackiq.com — Attack Graph Emulating The Conti Ransomware Teams Behaviors (report)
  • blog.bushidotoken.net — Lessons From Conti Leaks (report)
  • research.nccgroup.com — Adventures In The Land Of Bumblebee A New Malicious Loader (report)
  • thedfirreport.com — Bazarcall To Conti Ransomware Via Trickbot And Cobalt Strike (report)

External references