WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Security Awareness – Phishing Campaign Abuses CSV Text Files to Install BazarBackdoor
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Phishing Campaign Abuses CSV Text Files to Install BazarBackdoor

Author: Alec Davison

Created: Thursday, February 3, 2022 - 19:07

Categories: Cybersecurity

A recently observed phishing campaign is utilizing malicious CSV text files to install the BazarLoader/BazarBackdoor trojan. BazarBackdoor is a backdoor malware created by the TrickBot gang to provide threat actors with remote access to a compromised device which can then be used to move laterally through a corporate network, install more malware, steal data, and deploy ransomware.

The phishing message professes to be “Payment Remittance Advice” and contains links to remote webpages that download a malicious CSV file. When the CSV file is opened in Excel, the application provides a security notice asking users if they want to “enable automatic update of links.” If the user clicks enable, another final notice will confirm this action. If the user confirms both prompts, Excel will launch a PowerShell script that ultimately downloads and executes BazarBackdoor. Despite the security reminders, people have been observed falling for this scam. According to AdvIntel CEO Vitali Kremez, “Based on our visibility into the BazarBackdoor telemetry, we have observed 102 actual non-sandbox corporate and government victims over the past two days from this phishing campaign.” Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar