Hornetsecurity has observed a malicious email campaign distributing the BazarLoader using termination as a lure. The campaign uses a link to Google Docs from where the BazarLoader malware executable is downloaded.
BazarLoader is a new malware loader attributed to a threat actor with a close relation to the TrickBot malware. The loader is also aptly named KEGTAP, as in device used to open a beer keg3, because it is used to “open” the network of victims for follow up malware in order to move laterally on the network and eventually deploy ransomware.
On 2020-10-13 at exactly 13:00 UTC Hornetsecurity registered the first emails of the new BazarLoader campaign:
The emails use a termination lure:
The URL in the email is a legitimate Google Doc URL:
From their all links lead to the BazarLoader executable (
When executed, BazarLoader will use OpenNIC Public DNS Servers to resolve a
.bazar domain generated via domain generation algorithm (DGA). The
.bazar domain is not a regular TLD but rather an alternative DNS TLD of the decentralized EmerDNS blockchain DNS system.
Then the BazarLoader will download and install the BazarBackdoor1. This backdoor will be used to move laterally in the victim’s network in order to take over the domain controller. Eventually the intrusion is monetized by deploying the Ryuk2 ransomware.
Conclusion and Countermeasure
Because the payload download is hosted on the legitimate Google Docs site victims are more likely to click the link in the email then they would an obscure URL they are unfamiliar with. BazarLoader’s use of the EmerDNS blockchain DNS system makes it immune to current efforts by various security vendors to disrupt the operations of TrickBot.
Hornetsecurity’s Spam and Malware Protection, already detects and quarantines the outlined threat emails.
- 1 https://malpedia.caad.fkie.fraunhofer.de/details/win.bazarbackdoor
- 2 https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk
- 3 https://en.wikipedia.org/wiki/Beer_tap#Portable_keg_tap
Indicators of Compromise (IOCs)
OpenNIC Public Servers used by the analyzed BazarLoader version: