Skip to main content
Skip to main content
Microsoft Security Intelligence
11 entries found.
Updated on Feb 09, 2021

Microsoft Defender Antivirus detects and removes this threat.

BazaLoader, also known as Bazarloader, is a malware that is increasingly used in sophisticated threat campaigns. Attacks involving BazaLoader rely on social engineering and adopt distinctive attack chains designed to evade security solutions. Attackers send phishing emails that contain links to Google documents, which then lead to other documents embedded with links that download Bazaloader malware on the target device.

Bazaloader provides initial foothold and paves the way for hands-on-keyboard activity. It enables the delivery of second-stage toolkits, commonly Cobalt Strike, which in turn enable reconnaissance and lateral movement within the compromised network.

BazaLoader is a serious threat that is relatively proficient in evading certain detection mechanisms. It highlights the continued presence of human-operated ransomware and how these threats rely on common security weaknesses.

Read the following blogs for details:

Alert level: severe
Updated on Nov 03, 2020
Alert level: severe
Updated on Nov 03, 2020
Alert level: severe
Updated on Jul 27, 2021
Alert level: severe
Updated on Aug 06, 2021
Alert level: severe
Updated on Sep 08, 2021
Alert level: severe
Updated on May 24, 2022
Alert level: severe
Updated on Feb 16, 2021

Microsoft Defender Antivirus detects and removes this threat.

BazaLoader, also known as Bazarloader, is a malware that is increasingly used in sophisticated threat campaigns. Attacks involving BazaLoader rely on social engineering and adopt distinctive attack chains designed to evade security solutions. Attackers send phishing emails that contain links to Google documents, which then lead to other documents embedded with links that download Bazaloader malware on the target device.

Bazaloader provides initial foothold and paves the way for hands-on-keyboard activity. It enables the delivery of second-stage toolkits, commonly Cobalt Strike, which in turn enable reconnaissance and lateral movement within the compromised network.

BazaLoader is a serious threat that is relatively proficient in evading certain detection mechanisms. It highlights the continued presence of human-operated ransomware and how these threats rely on common security weaknesses.

Read the following blogs for details:

Alert level: severe
Updated on Sep 28, 2021
Alert level: severe
Updated on Nov 03, 2020
Alert level: severe
Updated on Aug 06, 2021
Alert level: severe