Live Training | What's New in Lumu Defender

Already have an account? Sign in

Sign in

Malware

S0534

Bazar

Type

Downloader and dropper

Associated threat actors

Conti and Ryuk affiliates

Key Capabilities

Infiltrates systems to deliver other malicious payloads, such as ransomware or banking trojans.

OS Targeted

Windows

IoCs on Maltiverse

Maltiverse provides updated IoCs for easy SIEM/SOAR/Firewall/EDR integration.

What is Bazar?

Bazar (S0534), often called BazarLoader, is a sophisticated malware dropper. Its primary purpose is to serve as a gateway for other malicious payloads, like ransomware or banking trojans, by establishing an initial foothold in a network.

Bazar malware is known for its advanced evasion techniques, including obfuscation and encryption, which allow it to bypass traditional security measures.

How to Defend Against Bazar?

Defending against Bazar requires a multi-layered approach focused on blocking its delivery and detecting its stealthy execution.

  • Implement robust email security and education to block the phishing attempts that are a primary delivery vector for this downloader.
  • Keep all software and systems patched to limit the vulnerabilities that can be exploited for initial access.
  • Deploy endpoint detection and antivirus to identify and block the execution of the loader and its evasive techniques.
  • Use network detection (NDR) with integrated threat intelligence to spot and block C2 communications associated with BazarLoader.

Join our pre-day 
workshop waitlist

By clicking “Submit Request” you agree to the Lumu Terms of Service and Privacy Policy.