logo

Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros

ID: 23977a37-cd47-5df3-bd5e-f2bd9781ac4a

STIX ID: report--23977a37-cd47-5df3-bd5e-f2bd9781ac4a

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2024-02-14

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Proofpoint researchers observed a resurgence of the Bumblebee loader in 2024 using a retro attack chain: phishing emails to US organizations (subject 'Voicemail February') point to OneDrive-hosted Word documents containing malicious VBA macros. The macro, if enabled, drops a script that executes PowerShell to download and run a Bumblebee DLL; historically Bumblebee has been used to deliver post-exploitation tools like Cobalt Strike. Indicators and mitigations (keep macros disabled, patch Office/Windows, user training) are provided, and attribution is uncertain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.