WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Security Awareness – BazarBackdoor Spreading via Corporate Contact Forms
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – BazarBackdoor Spreading via Corporate Contact Forms

Author: Alec Davison

Created: Tuesday, March 15, 2022 - 18:31

Categories: Cybersecurity

The BazarBackdoor malware has been observed spreading via corporate website contact forms rather than its typical phishing email attack chain, allowing it to evade security software. BazarBackdoor is a backdoor malware, which WaterISAC detailed last month, created by the TrickBot gang to provide threat actors with remote access to a compromised device which can then be used to move laterally through a corporate network, install more malware, steal data, and deploy ransomware. A new distribution campaign, identified in a report by Abnormal Security, exploits corporate contact forms to contact victim organizations. For instance, in one of the observed cases, the threat actors pretended to be an employee from a construction company submitting a request for a product quote. When the employee responds, the threat actors send back a malicious ISO file via a file-sharing service to circumvent security software. After the victim downloads the ISO file, BazarBackdoor infects the system. Researchers believe the threat actor’s goal is likely to deploy Cobalt Strike or ransomware. Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar