New Bumblebee Loader Infection Chain Signals Possible Resurgence
ID: b7e4d2f6-ee87-51a3-9e5e-3af1e5aa39f0
STIX ID: report--b7e4d2f6-ee87-51a3-9e5e-3af1e5aa39f0
Feed Name: Netskope Threat Labs
Netskope Threat Labs analyzed a Bumblebee downloader campaign that begins with phishing-delivered ZIP/LNK files which invoke PowerShell to fetch an MSI; the MSI uses the SelfReg table to load a malicious DLL into msiexec and execute DllRegisterServer, unpacking the Bumblebee payload entirely in memory. This technique avoids writing the payload to disk and reduces noisy process creation, and the campaign is notable as a potential resurgence of Bumblebee delivering Cobalt Strike beacons and ransomware; IOCs and detections are provided by Netskope.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
