Bazar
MITRE ATT&CK: S0534 View on attack.mitre.org
Aliases: KEGTAP, Team9, Bazaloader, BEERBOT, Team9Backdoor, bazaloader, bazarloader, Bazar
- First seen
- 2020-04-01 00:00:00
- Malware type
- backdoor, loader, downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 178 (134 malicious)
- Last IoC activity
- 2026-09-02 02:42:55
- Profile updated
- 2026-07-07 12:37:50
Targeted industries: professional-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:us country_code:de
Context
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.
Recent IoC activity
134 malicious indicators in Maltiverse are attributed to Bazar (S0534). The 20 most recently updated:
Detection coverage
- 5 YARA rules
- 909 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Domain Account (attack-pattern)
- Remote System Discovery (attack-pattern)
- Malicious Link (attack-pattern)
- Network Share Discovery (attack-pattern)
- Process Injection (attack-pattern)
- BITS Jobs (attack-pattern)
- Windows Command Shell (attack-pattern)
- PowerShell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Security Software Discovery (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Process Doppelgänging (attack-pattern)
- Clear Persistence (attack-pattern)
- Data from Local System (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- System Language Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Multi-Stage Channels (attack-pattern)
- Query Registry (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Software Discovery (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
- EXOTIC LILY (threat-actor)
- C0015 (campaign)
Detection rules
- ARKBIRD_SOLG_MAL_Bazarloader_Oct_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Bazarloader (yara-rule)
- DITEKSHEN_MALWARE_Win_UNK05 (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Bazarloader (yara-rule)
- CAPE_Bazar (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- CrowdStrike — Report2021Gtr (report)
- twitter.com — 1321865315513520128 (report)
- Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
- blog.google — Exposing Initial Access Broker Ties Conti (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- trellix.com — Evolution Of Bazarcall Social Engineering Tactics (report)
- Microsoft — Bazacall Phony Call Centers Lead To Exfiltration And Ransomware (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
- Palo Alto Unit 42 — Luna Moth Callback Phishing (report)
- securityintelligence.com — Trickbot Gang Doubles Down Enterprise Infection (report)
- CrowdStrike — Wizard Spider Adversary Update (report)
- Trend Micro — Rpt Navigating New Frontiers Trend Micro 2021 Annual Cybersecurity Report (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
- attackiq.com — Attack Graph Emulating The Conti Ransomware Teams Behaviors (report)
- blog.bushidotoken.net — Lessons From Conti Leaks (report)
- research.nccgroup.com — Adventures In The Land Of Bumblebee A New Malicious Loader (report)
- thedfirreport.com — Bazarcall To Conti Ransomware Via Trickbot And Cobalt Strike (report)
External references
- mitre-attack — S0534
- Team9
- KEGTAP
- Bazaloader
- Cybereason Bazar July 2020
- FireEye KEGTAP SINGLEMALT October 2020
- Microsoft Ransomware as a Service
- NCC Group Team9 June 2020
- CrowdStrike Wizard Spider October 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy