BumbleBee: A new trendy loader for Initial Access Brokers
ID: 9678f22f-3e23-5123-bcbf-bb398f2f4a06
STIX ID: report--9678f22f-3e23-5123-bcbf-bb398f2f4a06
Feed Name: Sekoia.com
Threat Score
**Executive Summary:** BumbleBee is a recently observed sophisticated loader distributed via spearphishing (ZIP->ISO->LNK) by Initial Access Brokers to deploy secondary payloads (Cobalt Strike, Meterpreter, ransomware families); it uses anti-analysis checks, in-memory PE loading, and RC4-obfuscated C2/campaign identifiers, and the report provides technical analysis, YARA rules, tracked C2 IPs, and sample hashes for detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
