logo

In-depth analysis of the new Team9 malware family

ID: ae0c13d5-237e-5e63-bad3-5c90df660d85

STIX ID: report--ae0c13d5-237e-5e63-bad3-5c90df660d85

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2020-06-02

Date Updated: 2026-04-27

...
...

This technical analysis from NCC Group/RIFT details the Team9 (Bazar) malware family (linked to the Trickbot group), describing two loader variants and the backdoor: their persistence methods (Run key, scheduled tasks, Winlogon hijack, shortcut hijacks), anti-analysis techniques (delays, API-hook detection, ntdll opcode checks), payload delivery and process injection methods (process hollowing, Doppelgänging), network C2 behavior over HTTP/HTTPS using Emercoin .bazar domains and IP addresses, and includes extensive IOCs (SHA-256 hashes, domains, C2 and DNS IP lists, mutex names and host indicators) to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.