logo

Spear Phishing Campaign Delivers Buer & Bazar

ID: ad64e889-afe4-5f22-bdc1-5a6b5fc8fa97

STIX ID: report--ad64e889-afe4-5f22-bdc1-5a6b5fc8fa97

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ details a recent targeted spear-phishing campaign impersonating termination notices that uses Google Docs links to distribute payloads (primarily the Bazar backdoor and sometimes the Buer loader). The report covers the shared packer and headerless PE loader, C2/TLS characteristics, observed post-infection behavior including Cobalt Strike deployment, MITRE ATT&CK mappings, and provides MD5s, distribution URLs, C2 IPs, URIs, PDB strings, and additional indicators for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.