{"id":2876,"date":"2021-05-28T21:18:33","date_gmt":"2021-05-29T02:18:33","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2876"},"modified":"2021-05-28T21:18:34","modified_gmt":"2021-05-29T02:18:34","slug":"bazaloader-threat-posing-as-legitimate-sites","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/","title":{"rendered":"BazaLoader threat posing as legitimate sites"},"content":{"rendered":"\n<p>Proofpoint researchers identified a BazaLoader campaign that required significant human interaction to run and install the BazaLoader backdoor. The threat actor took advantage of telephone customer service representatives to instruct victims to unknowingly download and install the malware. This campaign is representative of a broader trend driven by BazaLoader threat actors using call centers as part of an intricate chain of attacks.<\/p>\n\n\n\n<p>On Wednesday, Proofpoint researchers said in a report that they observed BazaLoader for the first time in April 2020. Various threat actors are using the downloader, which is written in C ++, to load malware such as Ryuk and Conti ransomware. Additionally, Proofpoint researchers said they are confident that there is a &#8220;strong overlap&#8221; between the distribution and post-exploit activity of BazaLoader and the threat actors behind the Trickbot malware.<\/p>\n\n\n\n<p>This entertainment-themed campaign was first seen in early May 2021 and masqueraded as an entertainment streaming service, with a fancy website featuring fake movies. The campaign demonstrates an inversely proportional relationship between successful infection rates and asking people to complete complicated steps &#8211; the more steps the user requires, the less likely they are to complete the attack chain. However, despite being contradictory, the techniques used by threat actors in this and similar campaigns help bypass fully automated threat detection systems.<\/p>\n\n\n\n<p><strong><em>In the recent BazaLoader campaign, messages pretend to be from multiple senders with topics such as:<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Your trial period M0012064753012345 will expire soon. Fortunately, he made the decision to stay with us!<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>The demo stage has expired! Your account # M0272028060812345 will automatically be transferred to the premium plan!<\/p>\n\n\n\n<p>The emails contain phone numbers and references to the company &#8220;BravoMovies&#8221;. The messages are intended to inform the target that their credit card will be charged unless they unsubscribe from the service. If the user calls the phone number provided in the email, a customer service representative will verbally guide them to the alleged company website. The website is a compelling representation of a movie and television streaming service.<\/p>\n\n\n\n<p>When the user visits the mentioned site, navigates to the Frequently Asked Questions component of the website and follows the instructions to unsubscribe through the &#8220;Subscription&#8221; page, they will be directed to the download of an Excel Sheet. This is not the first time that Proofpoint has seen intricately composed BazaLoader email threat campaigns that have required a significant amount of human interaction, including customer service representatives over the phone, to trigger the malware download.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/hancitor-is-a-trojan-that-has-evolved\/\">Hancitor is a Trojan that has evolved<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/buer-malware-charger-emerges-on-the-web\/\">Buer Malware Charger Emerges on the Web<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Proofpoint researchers identified a BazaLoader campaign that required significant human interaction to run and install the BazaLoader backdoor. The threat actor took advantage of telephone customer service representatives to instruct victims to unknowingly download and install the malware. This campaign is representative of a broader trend driven by BazaLoader threat actors using call centers as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2877,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2876","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BazaLoader threat posing as legitimate sites - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BazaLoader threat posing as legitimate sites - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-29T02:18:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-29T02:18:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1109\" \/>\n\t<meta property=\"og:image:height\" content=\"740\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"BazaLoader threat posing as legitimate sites\",\"datePublished\":\"2021-05-29T02:18:33+00:00\",\"dateModified\":\"2021-05-29T02:18:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/\"},\"wordCount\":424,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/BazaL.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/\",\"name\":\"BazaLoader threat posing as legitimate sites - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/BazaL.jpg\",\"datePublished\":\"2021-05-29T02:18:33+00:00\",\"dateModified\":\"2021-05-29T02:18:34+00:00\",\"description\":\"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/BazaL.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/BazaL.jpg\",\"width\":1109,\"height\":740},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/bazaloader-threat-posing-as-legitimate-sites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BazaLoader threat posing as legitimate sites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BazaLoader threat posing as legitimate sites - Truxgo Server Blog","description":"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/","og_locale":"es_MX","og_type":"article","og_title":"BazaLoader threat posing as legitimate sites - Truxgo Server Blog","og_description":"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...","og_url":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-29T02:18:33+00:00","article_modified_time":"2021-05-29T02:18:34+00:00","og_image":[{"width":1109,"height":740,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"BazaLoader threat posing as legitimate sites","datePublished":"2021-05-29T02:18:33+00:00","dateModified":"2021-05-29T02:18:34+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/"},"wordCount":424,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/","url":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/","name":"BazaLoader threat posing as legitimate sites - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg","datePublished":"2021-05-29T02:18:33+00:00","dateModified":"2021-05-29T02:18:34+00:00","description":"The entertainment pages movies, series, are very popular among users, and criminals take advantage of it with the threat called BazaLoader...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/BazaL.jpg","width":1109,"height":740},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/bazaloader-threat-posing-as-legitimate-sites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"BazaLoader threat posing as legitimate sites"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2876"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2876\/revisions"}],"predecessor-version":[{"id":2888,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2876\/revisions\/2888"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2877"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}