Spear Phishing Campaign Delivers Buer & Bazar
ID: ad64e889-afe4-5f22-bdc1-5a6b5fc8fa97
STIX ID: report--ad64e889-afe4-5f22-bdc1-5a6b5fc8fa97
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ details a recent targeted spear-phishing campaign impersonating termination notices that uses Google Docs links to distribute payloads (primarily the Bazar backdoor and sometimes the Buer loader). The report covers the shared packer and headerless PE loader, C2/TLS characteristics, observed post-infection behavior including Cobalt Strike deployment, MITRE ATT&CK mappings, and provides MD5s, distribution URLs, C2 IPs, URIs, PDB strings, and additional indicators for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
