New BazaFlix Attack Pushes BazarLoader Malware Via Fake Movie Site

New BazaFlix Attack Pushes BazarLoader Malware Via Fake Movie Site

Security researchers found a new BazarCall email phishing campaign that manages to bypass automated threat detection systems to deliver the BazarLoader malware used by the TrickBot gang.

A new wave of BazarCall emails were spotted at the beginning of the month, pretending to be a notification about a payment card charge for continued subscription to an online service.

Cancel video streaming subscription

BazarCall is a new phishing method in use since the beginning of the year that relies on call centers to direct users to downloading malware laced documents.

Also Read: Data Protection Officer Singapore | 10 FAQs

It relies heavily on social engineering and user interaction, starting with a notification about the end of a trial period for a service and starting to charge for a subscription.

In the recent campaign caught by researchers at Proofpoint, the messages purported to be from a streaming entertainment service announcing that the trial/demo is about to expire and that their payment card is about to be charged for a premium plan.

source: Proofpoint

The emails come with a phone number that recipients can call to cancel the subscription. However, the directions received from the other end of the line point to the website of an alleged streaming and TV service called “BravoMovies” from company called UrbanCinema. For this reason, Proofpoint uses the name BazaFlix to track this campaign.

The researchers say that the website looks realistic enough, using movie posters from various public sources, “including an advertising agency, the creative social network Behance, and the book “How to Steal a Dog.”

Following the instructions to unsubscribe from BravosMovies streaming services users get to download a malicious Excel document with macros that install BazarLoader malware.

source: Proofpoint

Although the malware is used to download and execute other malicious files, the researchers said that they did not observe a second-stage payload for this campaign.

BazarLoader emerged in April last year and due to code similarities and infrastructure used it is believed to have the same developers as the TrickBot trojan.

The TrickBot gang is infamous for distributing Ryuk and Conti ransomware to valuable targets (corporate victims) and BazarLoader is another tool to avoid using the the highly-detected trojan.

The BazaCall malware delivery method started being used in late January and continued through the end of March. Although the technique remains the same same, the threat actors used various themes to trap victims.

Previous campaigns lured with fake subscriptions associated to companies in the pharmaceutical, flower, lingerie, medical, or antivirus businesses.

While both BazarLoader and TrickBot are believed to be created by the same group, the call centers may be operated by a different gang, who are renting them for malware distribution.

Also Read: Practitioner Certificate in Personal Data Protection: Everything You Need to Know

To show what happens when an unsuspecting BazaCall victim calls the phone number in the phishing email, security researcher Brad Duncan shared a video with the dialog with the threat actor’s call center.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

1 week ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

2 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago