#bazarloader

Just Another Blue TeamerLeeArchinal@ioc.exchange
2023-09-17

Happy Sunday!

The Intel 471 team provides their findings of the #BumbleBee loader as it makes its comeback after a two month break. Taking the place of the #BazarLoader (the source code was leaked when the #Conti leak occurred). The BumbleBee loader has been associated with distributing ransomware and is currently being used by multiple threat actors. My favorite part of this article though (and not surprising) is all the MITRE ATT&CK mappings that provide all the #ThreatHunters a place to start looking, so thank you for that team! I hope you all enjoy and Happy Hunting!

Bumblebee Loader Resurfaces in New Campaign
intel471.com/blog/bumblebee-lo

#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

From source
𝙽𝙴𝚃𝚁𝙴𝚂𝙴𝙲netresec@infosec.exchange
2023-04-15

#BazarLoader / #BazarBackdoor also uses the BackConnect protocol do deploy reverse VNC. This screenshot is from @malware_traffic's 2021-11-05 Bazar PCAP. The #BackConnect server was running on 87.120.8.190:9090

Bazar reverse VNC traffic to 87.120.8.190:9090
2021-08-03

BazarCaller – the malware gang that talks you into infecting yourself - Calling someone back feels safer than clicking an unknown link... but it isn't! Remind yo... nakedsecurity.sophos.com/2021/ #bazarloader #bazacaller #bazaloader #microsoft #malware #scam

2021-01-26

Threat Roundup for January 8 to January 15 - Today, Talos is publishing a glimpse into the most prevalent threats we've observed between Jan. 8 a... feedproxy.google.com/~r/feedbu #vulnerabilities #fickerstealer #threatroundup #bazarloader #ciscotalos #glupteba #malware #redline #bunitu #dridex #expiro #tofsee #zegost #talos

2020-10-24

IT-гигант Sopra Steria подвергся атаке вымогательского ПО Ryuk #кибератака, #Ryuk, #TrickBot, #BazarLoader securitylab.ru/news/513326.php twitter.com/SecurityLabnews/st

2020-10-19

Ryuk Ransomware Gang Uses Zerologon Bug for Lightning-Fast Attack - Researchers said the group was able to move from initial phish to full domain-wide encryption in j... threatpost.com/ryuk-ransomware #initialphishingemail #privilegeescalation #vulnerabilities #activedirectory #attackanalysis #cve-2020-1472 #cobaltstrike #websecurity #bazarloader #dfirreport #fivehours #zerologon #malware #ryuk

2020-10-14

Операторы TrickBot используют вредонос BazarLoader для загрузки Ryuk #TrickBot, #BazarLoader securitylab.ru/news/513052.php twitter.com/SecurityLabnews/st

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst