B aza (BazarLoader & BazarBackdoor) has been attributed to the organized cybercrime group behind Trickbot by multiple security vendors over the past year.
BazarBackdoor
BazarBackdoor is a Windows backdoor associated with the TrickBot ecosystem, commonly attributed to ITG23/Wizard Spider.
BazarBackdoor
Family profile
BazarBackdoor is a Windows backdoor associated with the TrickBot ecosystem, commonly attributed to ITG23/Wizard Spider. First identified in 2020, it was frequently deployed by BazarLoader and used to establish remote access to enterprise environments for follow-on intrusion activity, including Cobalt Strike deployment and Conti or Ryuk ransomware operations. The names BazarBackdoor and BazarLoader have at times been used interchangeably, although BazarLoader is more specifically characterized as the loader that retrieves the backdoor.
BazarBackdoor has been distributed through phishing campaigns using social-engineering themes such as employment termination, customer complaints, invoices, and payment notices. Delivery chains have used malicious documents, archives, CSV files abusing Excel DDE, JavaScript, and links through document-hosting services. It can communicate with command-and-control infrastructure, retrieve additional payloads, and execute filelessly through process hollowing and process doppelgänging. Observed variants established persistence using scheduled tasks and used decentralized DNS/DGA-based resolution for command-and-control communications. Access provided by BazarBackdoor has supported reconnaissance, credential theft, lateral movement, data theft, and ransomware deployment against corporate networks.
Capabilities
- Defense Evasion
- Initial Access
- Lateral Movement
- Persistence
- Post Exploitation
- Process Injection
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
5 named in public reportingThe TrickBot Gang is most known for its namesake, the TrickBot banking trojan, but is also behind the development of the BazarBackdoor and Anchor backdoors.
According to a separate report published by Advanced Intelligence (AdvIntel) last week, the Conti ransomware cartel is believed to have acqui-hired several elite developers of TrickBot to retire the malware and switch to upgraded variants such as BazarBackdoor.
In October 2021, the IBM X-Force reported that the threat group ITG23 ... had partnered with Shathak ... to distribute the TrickBot and the BazarBackdoor (also referred to as BazarLoader) malware.
We track the use of BAZARLOADER and BAZARBACKDOOR as UNC2053.
Exploited software
Vulnerabilities linked to BazarBackdoor
2 CVEsMITRE ATT&CK