Bumblebee malware returns after recent law enforcement disruption
ID: 70ccecff-e617-5d32-9252-c3c0d577537b
STIX ID: report--70ccecff-e617-5d32-9252-c3c0d577537b
Feed Name: Bleeping Computer
Threat Score
**Bumblebee loader resurgence observed:** Netskope reports renewed Bumblebee activity months after Operation Endgame, using phishing LNK shortcuts that trigger MSI installers executed by msiexec to load the loader in memory; the samples use an RC4 key "NEW_BLACK" and campaign IDs "msi"/"lnk001", and Bumblebee is known to deliver Cobalt Strike, information stealers, and ransomware—IOC lists have been published on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
