Skip to main content
QUIETLYTIC
Malware

Bazar

Downloader and backdoor, per MITRE ATT&CK, active since at least April 2020 against professional services, healthcare, manufacturing, IT, logistics, and travel companies, reportedly tied to TrickBot campaigns.

Threat Level
HIGH
Family
Bazar
Type
TROJAN
Also Known As
KEGTAP, Team9, Bazaloader

Overview

Bazar (MITRE ATT&CK ID S0534) is a downloader and backdoor that has been used since at least April 2020, per MITRE’s software profile, with infections primarily against professional services, healthcare, manufacturing, IT, logistics, and travel companies across the US and Europe. MITRE documents Bazar as reportedly tied to TrickBot campaigns, capable of deploying additional malware — including ransomware — and stealing sensitive data.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links Bazar to two distinct MITRE ATT&CK groups: EXOTIC LILY and Wizard Spider — the latter also TrickBot’s documented operator, consistent with MITRE’s noted ties between the two malware families.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to Bazar in our data include Asymmetric Cryptography (T1573.002), BITS Jobs (T1197), Clear Persistence (T1070.009), Code Signing (T1553.002), Data from Local System (T1005), Deobfuscate/Decode Files or Information (T1140), Disable or Modify Tools (T1685), and Domain Account discovery (T1087.002).

What we don’t have

MITRE’s description gives an explicit origin (“at least April 2020”) but our ingested data doesn’t carry it as a structured discovery-date field. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What is Bazar? A downloader and backdoor, per MITRE ATT&CK, active since at least April 2020, used to deploy additional malware including ransomware and to steal sensitive data.

Is Bazar related to TrickBot? Per MITRE’s documentation, Bazar “reportedly has ties to TrickBot campaigns,” and both are linked to the group Wizard Spider in our relationship data.

Which industries has Bazar targeted? Per MITRE’s description: professional services, healthcare, manufacturing, IT, logistics, and travel companies, primarily across the US and Europe.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0534, aggregated September 8, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools