Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

BazarBackdoor Uses Compressed Files To Deliver Malware

BazarBackdoor Uses Compressed Files To Deliver Malware

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

Security researchers have spotted a new phishing campaign in the wild that you'll want to make a note of. In this case the hackers are attempting to deliver a malware strain known as BazarBackdoor by using an innovative compression technique and then disguising the malware as an image file.

Multi-compression isn't a new technique but it has never been widely used. Although it does seem to be enjoying a surge in popularity lately among the hackers of the world. That is mostly because it's pretty good at 'tricking' email security systems into thinking and flagging malicious attachments as clean.

By itself BazarBackdoor isn't harmful but it opens the door and installs a perfectly legitimate toolkit called Cobalt Strike. That then allows the hackers to do pretty much anything they like from moving laterally inside your network, to launching ransomware attacks, copying and exfiltrating files, deleting files, or launching some other type of malware.

Even more disturbing is that earlier this year security researchers discovered a variant of BazarBackdoor written in a programming language called Nim which provides at least some evidence that this particular strain is increasing in popularity among hackers around the world.

Education is the key just like it always has been. Let your employees know to be on their guard and not to download any attachment (no matter how innocent looking) that comes from an address they do not know and are not familiar with.

Even that isn't perfect protection but it's certainly a powerful step in the right direction that will mitigate your risk.

Campaigns like this are further evidence that hackers are evolving and their tactics are becoming ever more sophisticated. The challenge in the year ahead and beyond will be to evolve even more quickly than the hackers are. At present it is not clear whether most companies can manage that feat.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime