logo

New Trickbot and BazarLoader delivery vectors

ID: 54a0f646-c43f-5d98-933c-a7107af9a4d6

STIX ID: report--54a0f646-c43f-5d98-933c-a7107af9a4d6

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz details active Trickbot and BazarLoader campaigns that use heavily obfuscated JavaScript, LNK files, and malicious Office attachments to deliver multi-stage payloads with sandbox-evasion techniques, documents execution flows (wscript/cmd/powershell/mshta), maps to MITRE ATT&CK techniques, and provides IoCs (file hashes, malicious URLs and C2 domains) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.