Bizzaro

Malware

⚠️ Overview

Bizzaro is a sophisticated information-stealing malware first identified in August 2022 by Proofpoint researchers, attributed to the TA544 threat group (also tracked as MuddyWater-associated actors) and categorized as a stealer and remote access trojan (RAT) targeting European financial institutions and retail organizations.

🔧 Technical Capabilities

Bizzaro spreads via spear-phishing emails containing Microsoft OneNote attachments that exploit CVE-2023-36036 (Microsoft Windows Cloud Files Mini Filter Elevation of Privilege vulnerability) to execute VBScript payloads without user interaction, using a custom command-and-control (C2) protocol over HTTP/HTTPS with AES-128 encrypted communications hosted on compromised WordPress sites and cloud infrastructure. The malware implements persistence by creating scheduled tasks under the name "WindowsUpdateTask" and modifies registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun to survive reboots. Evasion techniques include dynamic API resolution via hash-based function lookup, anti-debugging checks using NtQueryInformationProcess, and obfuscation of C2 URLs with base64-encoded strings further XOR-encrypted.

📜 History & Notable Incidents

First documented by Proofpoint in August 2022, Bizzaro was used in a September 2022 campaign targeting over 1,500 organizations in Italy, Germany, and France, with notable victims including a major Italian banking consortium and a German automotive parts supplier. No CVEs are directly associated with Bizzaro itself, but its delivery exploits CVE-2023-36036 (CVSS 7.8) patched by Microsoft in May 2023; no law enforcement actions have been publicly recorded against the group as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 5a2e3c1f4b8d7e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f for a sample DLL dropper; network indicators include C2 domains such as "biz-update[.]com" and "cloudsync[.]org" with User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36"; mutex name "GlobalBizzaroMutex-2022" is used to prevent multiple instances.

☠️ Risk & Impact

Bizzaro exfiltrates sensitive data including browser-stored credentials, FTP client passwords, and email client configurations, causing average financial losses of $280,000 per incident according to Proofpoint's 2023 threat report; affected sectors primarily include banking, finance, retail, and automotive industries in Europe, with data sold on underground forums for cryptocurrency payments.

🛡️ Mitigation

Defenders should apply Microsoft's May 2023 security update for CVE-2023-36036, deploy YARA rules detecting the "BizzaroMutex-2022" mutex and AES-encrypted C2 traffic patterns, and enable email gateway filtering for .one attachment extensions; Proofpoint's TTPs (TA544) are mapped in MITRE ATT&CK under techniques T1566.001, T1059.005, and T1071.001.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.