logo

Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros

ID: 36251a19-d5ca-57d1-bfb3-316c5f0cb719

STIX ID: report--36251a19-d5ca-57d1-bfb3-316c5f0cb719

Feed Name: Proofpoint Blog

Threat Score
45/100

Date Published: 2024-02-14

Date Updated: 2026-04-28

...
...

Proofpoint researchers observed a renewed Bumblebee loader campaign targeting US organizations using emails with the subject "Voicemail February" that link to OneDrive-hosted Word documents embedding malicious VBA macros; the macro writes a script in the Windows temp directory which runs PowerShell to download and execute the Bumblebee DLL. While Bumblebee historically delivered post-exploitation tools like Cobalt Strike and Sliver, this campaign uses an outdated macro vector, shows limited use compared to other Bumblebee tactics, and has not been attributed to a tracked threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.