logo

Bumblebee malware attacks are back after 4-month break

ID: 4e9615c2-a5f7-5547-85cd-1a1a603930f9

STIX ID: report--4e9615c2-a5f7-5547-85cd-1a1a603930f9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint observed a large-scale phishing campaign delivering the Bumblebee malware loader via voicemail-themed emails that link to OneDrive-hosted macro-enabled Word documents; the macros create a script that runs a PowerShell chain to fetch and execute the Bumblebee DLL (w_ver.dll), enabling follow-on payloads like Cobalt Strike and potential ransomware deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.