logo

Adventures in the land of BumbleBee – a new malicious loader

ID: 9d3646d8-e6e1-5470-b562-e3a265d0ab77

STIX ID: report--9d3646d8-e6e1-5470-b562-e3a265d0ab77

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2025-01-15

Date Updated: 2026-08-03

...
...

This report details NCC Group's analysis of BUMBLEBEE, a actively developed malicious Windows loader that employs anti-analysis techniques, process injection, and RC4-encrypted HTTPS C2 communications to fetch and execute payloads (notably Cobalt Strike and Meterpreter). It documents distribution methods (ISO, OneDrive, email thread hijacking), task types, persistence mechanisms, embedded libraries/compile-time details, evolving behavior, and a long list of IOCs tied to multiple operator group tags.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.