Bumblebee malware attacks are back after 4-month break
ID: 4e9615c2-a5f7-5547-85cd-1a1a603930f9
STIX ID: report--4e9615c2-a5f7-5547-85cd-1a1a603930f9
Feed Name: Bleeping Computer
Threat Score
Proofpoint observed a large-scale phishing campaign delivering the Bumblebee malware loader via voicemail-themed emails that link to OneDrive-hosted macro-enabled Word documents; the macros create a script that runs a PowerShell chain to fetch and execute the Bumblebee DLL (w_ver.dll), enabling follow-on payloads like Cobalt Strike and potential ransomware deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
