Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros
ID: 23977a37-cd47-5df3-bd5e-f2bd9781ac4a
STIX ID: report--23977a37-cd47-5df3-bd5e-f2bd9781ac4a
Feed Name: The Register (Security)
Proofpoint researchers observed a resurgence of the Bumblebee loader in 2024 using a retro attack chain: phishing emails to US organizations (subject 'Voicemail February') point to OneDrive-hosted Word documents containing malicious VBA macros. The macro, if enabled, drops a script that executes PowerShell to download and run a Bumblebee DLL; historically Bumblebee has been used to deliver post-exploitation tools like Cobalt Strike. Indicators and mitigations (keep macros disabled, patch Office/Windows, user training) are provided, and attribution is uncertain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
