Skip to content

Malware

BazarBackdoor

aka BEERBOT · KEGTAP · Team9Backdoor · bazaloader · bazarloader

BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor.

BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader).

For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.


Family metadata imported from Malpedia (Fraunhofer FKIE).