WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Security Awareness – Phishing Campaign Abuses CSV Text Files to Install BazarBackdoor
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Phishing Campaign Abuses CSV Text Files to Install BazarBackdoor

Author: Alec Davison

Created: Thursday, February 3, 2022 - 19:07

Categories: Cybersecurity

A recently observed phishing campaign is utilizing malicious CSV text files to install the BazarLoader/BazarBackdoor trojan. BazarBackdoor is a backdoor malware created by the TrickBot gang to provide threat actors with remote access to a compromised device which can then be used to move laterally through a corporate network, install more malware, steal data, and deploy ransomware.

The phishing message professes to be “Payment Remittance Advice” and contains links to remote webpages that download a malicious CSV file. When the CSV file is opened in Excel, the application provides a security notice asking users if they want to “enable automatic update of links.” If the user clicks enable, another final notice will confirm this action. If the user confirms both prompts, Excel will launch a PowerShell script that ultimately downloads and executes BazarBackdoor. Despite the security reminders, people have been observed falling for this scam. According to AdvIntel CEO Vitali Kremez, “Based on our visibility into the BazarBackdoor telemetry, we have observed 102 actual non-sandbox corporate and government victims over the past two days from this phishing campaign.” Read more at BleepingComputer.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar