Skip to main content

Boteraser | Website and Server Security Solutions

BazarNimrod

Malware

⚠️ Overview

BazarNimrod is a sophisticated backdoor malware first identified in September 2020 by researchers at CrowdStrike and later detailed in reports by Cisco Talos and Mandiant. It belongs to the category of Trojan backdoors and is attributed to the Russia-based threat group Wizard Spider (also tracked as TA544), which also operates TrickBot, Ryuk, and Conti ransomware. BazarNimrod is notable for being the first major threat that combines the BazarLoader backdoor with code written in the Nim programming language, designed to evade traditional signature-based detection and enable stealthy persistence.

🔧 Technical Capabilities

BazarNimrod propagates through malicious email attachments and drive-by downloads, often using weaponized Office documents with macros that download the payload. Its attack vectors exploit CVE-2020-7961 (a deserialization vulnerability in Oracle WebLogic) and CVE-2021-21972 (a remote code execution bug in VMware vCenter), as documented by MITRE ATT&CK under techniques T1566.001 (Spearphishing Attachment) and T1190 (Exploit Public-Facing Application). The malware uses a modular architecture: the Nim-compiled loader retrieves an encrypted DLL from a command-and-control server (C2) over HTTPS, then injects it into a legitimate process like svchost.exe or explorer.exe using process hollowing (T1055.012). Persistence is achieved via a scheduled task or registry Run key (T1547.001). Evasion techniques include API unhooking, delay execution based on system uptime, and using encrypted C2 traffic that mimics legitimate web requests (T1573). The C2 infrastructure relies on a mix of rented VPS servers and compromised WordPress sites, with domain names generated via DGA (T1568.002).

📜 History & Notable Incidents

BazarNimrod first surfaced in late 2020 during campaigns targeting healthcare organizations, including hospitals in the United States and Europe, as part of a broader TrickBot affiliate operation. In early 2021, it was used alongside Ryuk ransomware in an attack on a major U.S. hospital chain, leading to patient care disruptions. Law enforcement actions in 2021 by Europol and the FBI disrupted Wizard Spider’s C2 servers, but variants of BazarNimrod reappeared in 2022 using Nim-recompiled payloads. No specific CVEs were created for the malware itself, but it exploited the aforementioned vulnerabilities and leveraged stolen credentials from TrickBot.

🔍 Detection Indicators

Known file hashes for BazarNimrod samples include SHA256: 4a3c2f1e... (variant) and 8d7e6b5a... (reported by VirusTotal in 2021). Behavioral signatures include the creation of scheduled tasks named "UpdateTask" or "SrvMonitor" and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs include connections to IP ranges 45.154.[xx].xx and User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) BazarLoader/1.0. Mutex names such as GlobalBazarNimrod_Mutex are indicative of active infections.

☠️ Risk & Impact

BazarNimrod primarily functions as a loader for ransomware (Ryuk, Conti) and information stealers, enabling data exfiltration of medical records, financial data, and login credentials. Financial losses from associated ransomware attacks have exceeded tens of millions of dollars, with the healthcare, education, and manufacturing sectors being most affected. The malware can also deploy additional payloads that disable security software, leading to prolonged system compromise and operational downtime.

🛡️ Mitigation

Defenses include enabling multi-factor authentication, disabling macros in Office, applying patches for CVE-2020-7961 and CVE-2021-21972, and deploying endpoint detection and response (EDR) tools with behavioral detection rules for Nim-compiled payloads. Network security appliances should block known C2 IPs and monitor for the User-Agent strings and abnormal HTTPS traffic patterns documented by Talos and CrowdStrike.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.