logo

Bumblebee malware returns after recent law enforcement disruption

ID: 70ccecff-e617-5d32-9252-c3c0d577537b

STIX ID: report--70ccecff-e617-5d32-9252-c3c0d577537b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Bumblebee loader resurgence observed:** Netskope reports renewed Bumblebee activity months after Operation Endgame, using phishing LNK shortcuts that trigger MSI installers executed by msiexec to load the loader in memory; the samples use an RC4 key "NEW_BLACK" and campaign IDs "msi"/"lnk001", and Bumblebee is known to deliver Cobalt Strike, information stealers, and ransomware—IOC lists have been published on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.