S0534: Bazar
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.CitationCybereason Bazar July 2020
Security context for executives and security teams
Bazar matters because ATT&CK describes it as a Windows downloader and backdoor associated with intrusions that can lead to additional malware deployment, sensitive data theft, and ransomware. For leaders, the key decision value is not simply “do we block Bazar,” but whether the organization can detect and contain a Windows foothold that performs discovery, persistence, command-and-control fallback, obfuscation, process injection, and follow-on payload delivery before it becomes a broader ransomware or data-loss event.
Executive priority
Prioritize Bazar as a resilience and incident-readiness scenario for Windows environments, especially where ransomware would materially affect operations. ATT&CK links Bazar to a ransomware intrusion campaign using Bazar, Cobalt Strike, and Conti, and to financially motivated groups including Wizard Spider and EXOTIC LILY. Executives should ask whether the SOC can rapidly confirm endpoint scope, identify scheduled-task or WMI-based persistence/execution, validate command-and-control activity including fallback channels, and preserve evidence for incident response, insurance, and compliance needs.
Technical view
SOC and IR teams should validate coverage against the ATT&CK techniques associated with this malware rather than relying on a named-malware alert. Relevant behaviors include Windows registry queries, network and remote-system discovery, user and process discovery, PowerShell and Windows command shell execution, WMI execution, scheduled tasks, masqueraded tasks/services and filenames, double file extensions, file deletion, process injection variants, software packing, dynamic API resolution, encrypted or encoded files, and fallback command-and-control channels. Because official detection text is not provided, teams should test whether host, process, registry, task scheduler, WMI, script, file, and network telemetry can reconstruct the intrusion timeline.
Likely telemetry
- Windows endpoint process creation and command-line telemetry
- PowerShell execution logs and script block/module logging where available
- Windows command shell activity
- WMI operational logs and remote/local WMI execution evidence
- Scheduled task creation, modification, and execution events
Detection direction
- Build behavior-based detections around the related techniques, not only Bazar-specific signatures, because ATT&CK notes obfuscation behaviors such as packing, dynamic API resolution, and encrypted or encoded files.
- Tune for suspicious combinations: discovery commands followed by WMI, PowerShell or cmd execution; scheduled task creation with masqueraded names; process injection indicators; and outbound network activity with fallback patterns.
- Review false positives carefully for administrative tooling, since WMI, PowerShell, cmd, registry queries, and scheduled tasks are common in legitimate IT operations.
- Validate whether telemetry survives file deletion and whether IR teams can recover enough process, file, and network history after cleanup activity.
- Use the relationship context as a scenario: Bazar may be part of intrusions involving additional malware and ransomware, so alerts should trigger rapid scoping for lateral discovery, payload staging, and data-access indicators.
Mitigation priorities
- Harden and monitor Windows administrative execution paths first: PowerShell, cmd, WMI, and scheduled tasks.
- Enforce least privilege and administrative access controls to reduce the value of discovery, persistence, and execution opportunities.
- Improve endpoint prevention and EDR visibility for process injection, suspicious child processes, masquerading, and obfuscated executables.
- Strengthen egress monitoring and network controls so command-and-control and fallback communications are visible and interruptible.
- Prepare ransomware-oriented IR playbooks that include rapid host isolation, evidence preservation, credential review, and checks for additional payloads or sensitive-data access.
Additional notes and limits
ATT&CK identifies Bazar as a downloader and backdoor used since at least April 2020, primarily against professional services, healthcare, manufacturing, IT, logistics, and travel companies in the US and Europe. Relationship context connects it to campaign C0015 and groups Wizard Spider and EXOTIC LILY, and lists multiple techniques across execution, persistence, privilege escalation, defense evasion, discovery, collection, and command and control. Use those relationships to guide validation and tabletop exercises, but confirm applicability against the local Windows environment and business-critical systems.
The supplied object does not include official detection guidance, aliases, labels, or explicit tactics on the malware object itself. Some related techniques are multi-platform, but the Bazar object’s supported platform is Windows; defensive planning here should therefore be centered on Windows unless local intelligence supports broader scope. The relationship descriptions support ransomware and data-theft risk framing, but they do not prove current activity or exposure in any specific organization.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Bazar
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.CitationCybereason Bazar July 2020
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
