{"id":1958,"date":"2021-04-08T14:40:17","date_gmt":"2021-04-08T18:40:17","guid":{"rendered":"https:\/\/cyburityllc.com\/?p=1958"},"modified":"2022-02-27T20:28:17","modified_gmt":"2022-02-28T01:28:17","slug":"bazarloader-used-to-deploy-ryuk-ransomware-on-high-value-targets","status":"publish","type":"post","link":"https:\/\/dialer.one\/index.php\/bazarloader-used-to-deploy-ryuk-ransomware-on-high-value-targets\/","title":{"rendered":"BazarLoader used to deploy Ryuk ransomware on high-value targets"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">BazarLoader used to deploy Ryuk ransomware on high-value targets<\/h1>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2020\/10\/12\/trojan-horse-chip.jpg\" alt=\"Trojan Horse malware\" title=\"\"><\/figure><\/div>\n\n\n\n<p>The TrickBot gang operators are increasingly targeting high-value targets with the new stealthy BazarLoader trojan before deploying the Ryuk ransomware.<\/p>\n\n\n\n<p>For years, the TrickBot gang has been using their trojan to compromise enterprise networks by downloading different software modules used for specific behavior such as&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/trickbot-banking-trojan-now-steals-rdp-vnc-and-putty-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">stealing passwords<\/a>,&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/nworm-trickbot-gang-s-new-stealthy-malware-spreading-module\/\" target=\"_blank\" rel=\"noreferrer noopener\">spreading to other machines<\/a>, or even&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/trickbot-now-steals-windows-active-directory-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">stealing a domain&#8217;s Active Directory database<\/a>.<\/p>\n\n\n\n<p>As these modules have become heavily analyzed over time, security solutions have become better at detecting these modules before being utilized.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">From TrickBot to BazarLoader<\/h2>\n\n\n\n<p>In April 2020,&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/bazarbackdoor-trickbot-gang-s-new-stealthy-network-hacking-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">bleepingcomputer reported<\/a>&nbsp;that the TrickBot gang had started to use a new BazarLoader\/BazarBackdoor infection in phishing attacks.<\/p>\n\n\n\n<p>In a new report,&nbsp;<a href=\"https:\/\/www.advanced-intel.com\/\" rel=\"noreferrer noopener\" target=\"_blank\">Advanced Intel<\/a>&nbsp;security researchers&nbsp;<a href=\"https:\/\/www.advanced-intel.com\/post\/front-door-into-bazarbackdoor-stealthy-cybercrime-weapon\" target=\"_blank\" rel=\"noreferrer noopener\">explain<\/a>&nbsp;that instead of burning victims with the highly-detected TrickBot trojan, threat actors now favor BazarBackdoor as their tool of choice for high-value enterprise targets.<\/p>\n\n\n\n<p>&#8220;BazarBackdoor remains the covert malware relying upon minimal functionality while on the host producing high-value long-term infections due to its simplicity and external operation dependency to exploit more information later.&#8221;<\/p>\n\n\n\n<p>&#8220;In other words, the BazarBackdoor \u201cblending-in\u201c simplicity and obfuscation layer allows the payload to be a better choice for high-value targets,&#8221; Kremez told BleepingComputer in a conversation about their report.<\/p>\n\n\n\n<p>A BazarLoader compromise starts with a targeted phishing attack, as shown by a phishing email received by BleepingComputer in April.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/security\/phishing\/e\/employee-complaint\/phishing-email.jpg\" alt=\"BazarLoader phishing attack\" title=\"\"><figcaption><strong>BazarLoader phishing attack<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<p>After infecting a computer, BazarLoader will use process hollowing to inject the BazarBackdoor component into legitimate Windows processes such as cmd.exe, explorer.exe, and svchost.exe. A scheduled task is created to load BazarLoader every time a user logs into the system.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/malware\/b\/bazarbackdoor\/scheduled-task.jpg\" alt=\"BazarLoader scheduled task\" title=\"\"><figcaption><strong>BazarLoader scheduled task<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n<p>Eventually, BazarBackdoor will deploy a Cobalt Strike beacon, which provides remote access to threat actors who install post-exploitation tools such as BloodHound and Lasagne for mapping a Windows domain and extracting credentials.<\/p>\n\n\n\n<p>Ultimately, the attack leads to threat actors deploying Ryuk ransomware on the entire network and demand massive ransoms.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/malware\/b\/bazaloader\/increasing-usage\/bazarbackdoor-attack-flow.jpg\" alt=\"BazarBackdoor attack flow\" title=\"\"><figcaption><strong>BazarBackdoor attack flow<\/strong><br>Source: Advanced Intel<\/figcaption><\/figure><\/div>\n\n\n\n<p>Even with this increase in utilization, as BazarBackdoor requires a more significant amount of human-operation, Kremez believes that BazarLoader will be reserved for select targets.<\/p>\n\n\n\n<p>&#8220;The downside of hunting with BazarBackdoor is that it requires an expensive exploitation operation to pivot from the infections,&#8221; Kremez explained.<\/p>\n\n\n\n<p>For mass-distribution, we should continue to see TrickBot utilized for network compromise.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>Check out our <a href=\"https:\/\/dialer.one\/penetration-testing-services-overview\/\" target=\"_blank\" rel=\"noreferrer noopener\">FREE security audit<\/a> to see if you are a victim.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BazarLoader used to deploy Ryuk ransomware on high-value targets The TrickBot gang operators are increasingly targeting high-value targets with the new stealthy BazarLoader trojan before deploying the Ryuk ransomware. For years, the TrickBot gang has been using their trojan to compromise enterprise networks by downloading different software modules used for specific behavior such as&nbsp;stealing passwords,&nbsp;spreading [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1959,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[],"tags":[],"class_list":["post-1958","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/dialer.one\/wp-content\/uploads\/2021\/04\/trojan-horse-chip.jpg","jetpack-related-posts":[{"id":1949,"url":"https:\/\/dialer.one\/index.php\/what-is-bazarcall-malware\/","url_meta":{"origin":1958,"position":0},"title":"What is BazarCall malware?","author":"carpenox","date":"April 8, 2021","format":false,"excerpt":"What is BazarCall malware? Answer: Malware targeting VoIP servers. Read on. For the past two months, security researchers have been waging an online battle against a new 'BazarCall' malware that uses call centers to distribute some of the most damaging Windows malware. The new malware was discovered being distributed by\u2026","rel":"","context":"Similar post","block_context":{"text":"Similar post","link":""},"img":{"alt_text":"BazarCall","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/bazarcall-spam-example.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/bazarcall-spam-example.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/bazarcall-spam-example.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/bazarcall-spam-example.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/bazarcall-spam-example.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":2951,"url":"https:\/\/dialer.one\/index.php\/how-to-fix-the-perl-repo-for-vicibox-10leap-15-3\/","url_meta":{"origin":1958,"position":1},"title":"How To &#8211; Fix the Perl repo for ViciBox 10(Leap 15.3)","author":"carpenox","date":"May 30, 2023","format":false,"excerpt":"How To - Fix the Perl repo for ViciBox 10(Leap 15.3) If you've tried to update your ViciBox 10 system you'll see that the Perl repo gives an error and you can't update from that repo any longer. The reason for this is because Leap 15.3 has gone end of\u2026","rel":"","context":"In &quot;Vicidial&quot;","block_context":{"text":"Vicidial","link":"https:\/\/dialer.one\/index.php\/category\/vicidial\/"},"img":{"alt_text":"Repository 'openSUSE-Leap-15.2-PHP-Applications' is invalid.","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/03\/image-15.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/03\/image-15.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/03\/image-15.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/03\/image-15.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/03\/image-15.png?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":2673,"url":"https:\/\/dialer.one\/index.php\/how-to-use-firewalld-via-command-line\/","url_meta":{"origin":1958,"position":2},"title":"How to &#8211; Use Firewalld via command line","author":"carpenox","date":"August 31, 2022","format":false,"excerpt":"Hopefully this will help a lot of you that end up just not using a firewall at all because it intimidates you not knowing how to use it correctly. Well, I've just eliminated that excuse, so now I want to see more of you securing your servers and dialer systems.\u2026","rel":"","context":"In &quot;CyburDial&quot;","block_context":{"text":"CyburDial","link":"https:\/\/dialer.one\/index.php\/category\/cyburdial\/"},"img":{"alt_text":"Robots trying to hack in","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/08\/robot-hackers-tryin-to-break-into-servers-2.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/08\/robot-hackers-tryin-to-break-into-servers-2.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/08\/robot-hackers-tryin-to-break-into-servers-2.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/08\/robot-hackers-tryin-to-break-into-servers-2.jpg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":1977,"url":"https:\/\/dialer.one\/index.php\/how-to-secure-vicidial-correctly-part-1\/","url_meta":{"origin":1958,"position":3},"title":"How to &#8211; Secure Vicidial, correctly. Part 1","author":"carpenox","date":"April 10, 2021","format":false,"excerpt":"How to - Secure Vicidial, correctly. Part 1 This article will show you how to secure Vicidial server correctly. This is definitely one of the topics, that I am asked about the most, so with that being said, this will be a multipart series with different \"layers\" of security from\u2026","rel":"","context":"In &quot;Vicidial&quot;","block_context":{"text":"Vicidial","link":"https:\/\/dialer.one\/index.php\/category\/vicidial\/"},"img":{"alt_text":"secure vicidial","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/image-13.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/image-13.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/image-13.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/image-13.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/04\/image-13.png?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":2378,"url":"https:\/\/dialer.one\/index.php\/table-of-contents\/","url_meta":{"origin":1958,"position":4},"title":"Table of Contents &#8211; Knowledge Base","author":"carpenox","date":"March 7, 2022","format":false,"excerpt":"Welcome to my blog, some of you may know me from the ViciDial forums, I am carpenox and I am here to share my knowledge with everyone, for free!","rel":"","context":"In &quot;Vicidial&quot;","block_context":{"text":"Vicidial","link":"https:\/\/dialer.one\/index.php\/category\/vicidial\/"},"img":{"alt_text":"CyburDial","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/02\/image.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/02\/image.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/02\/image.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/02\/image.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2022\/02\/image.png?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":1714,"url":"https:\/\/dialer.one\/index.php\/cyburity-llc-brings-you-cyburdial-a-cloud-based-zero-trust-predictive-dialer\/","url_meta":{"origin":1958,"position":5},"title":"CyburDial -:- A Cloud Based &#8216;Zero Trust&#8217; Predictive Dialer","author":"carpenox","date":"March 22, 2021","format":false,"excerpt":"CyburDial -:- A Cloud Based 'Zero Trust' Predictive Dialer In this emerging world of ransomware, malware, and hacks such as SolarWinds becoming our everyday reality, how concerned are you with data security? How important is your privacy and sense of security? WCW I(World Cyber War) is right around the corner\u2026","rel":"","context":"In &quot;CyburDial&quot;","block_context":{"text":"CyburDial","link":"https:\/\/dialer.one\/index.php\/category\/cyburdial\/"},"img":{"alt_text":"CyburDial","src":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/03\/newwelcome.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/03\/newwelcome.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/03\/newwelcome.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/03\/newwelcome.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/dialer.one\/wp-content\/uploads\/2021\/03\/newwelcome.png?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/posts\/1958","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/comments?post=1958"}],"version-history":[{"count":0,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/posts\/1958\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/media\/1959"}],"wp:attachment":[{"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/media?parent=1958"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/categories?post=1958"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dialer.one\/index.php\/wp-json\/wp\/v2\/tags?post=1958"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}