Malware.View on attack.mitre.org
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Bazar can retrieve information from the infected machine. |
| T1008 Fallback Channels |
Bazar has the ability to use an alternative C2 server if the primary server fails. |
| T1012 Query Registry |
Bazar can query |
| T1016 System Network Configuration Discovery |
Bazar can collect the IP address and NetBIOS name of an infected machine. |
| T1018 Remote System Discovery |
Bazar can enumerate remote systems using |
| T1027.002 Software Packing |
Bazar has a variant with a packed payload. |
| T1027.007 Dynamic API Resolution |
Bazar can hash then resolve API calls at runtime. |
| T1027.013 Encrypted/Encoded File |
Bazar has used XOR, RSA2, and RC4 encrypted files. |
| T1033 System Owner/User Discovery |
Bazar can identify the username of the infected user. |
| T1036.004 Masquerade Task or Service |
Bazar can create a task named to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software. |
| T1036.007 Double File Extension |
The Bazar loader has used dual-extension executable files such as PreviewReport.DOC.exe. |
| T1047 Windows Management Instrumentation |
Bazar can execute a WMI query to gather information about the installed antivirus engine. |
| T1053.005 Scheduled Task |
Bazar can create a scheduled task for persistence. |
| T1055 Process Injection |
Bazar can inject code through calling |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.