logo

New Bumblebee Loader Infection Chain Signals Possible Resurgence

ID: b7e4d2f6-ee87-51a3-9e5e-3af1e5aa39f0

STIX ID: report--b7e4d2f6-ee87-51a3-9e5e-3af1e5aa39f0

Feed Name: Netskope Threat Labs

Threat Score
75/100

Date Published: 2024-10-18

Date Updated: 2026-04-28

Author: Leandro Fróes

...
...

Netskope Threat Labs analyzed a Bumblebee downloader campaign that begins with phishing-delivered ZIP/LNK files which invoke PowerShell to fetch an MSI; the MSI uses the SelfReg table to load a malicious DLL into msiexec and execute DllRegisterServer, unpacking the Bumblebee payload entirely in memory. This technique avoids writing the payload to disk and reduces noisy process creation, and the campaign is notable as a potential resurgence of Bumblebee delivering Cobalt Strike beacons and ransomware; IOCs and detections are provided by Netskope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.