Technical Analysis of Bumblebee Malware Loader
ID: 70f3e97f-e89f-5442-9dde-230882d71d66
STIX ID: report--70f3e97f-e89f-5442-9dde-230882d71d66
Feed Name: CloudSEK Blog
Bumblebee is a sophisticated malware loader delivered via malicious ISO attachments (often in thread‑hijacked emails) that unpacks an embedded DLL, installs in-line hooks on ntdll functions to hollow gdiplus.dll with the final payload, and performs extensive anti‑VM, persistence, token manipulation, and code‑injection techniques; it has been observed delivering Cobalt Strike and Meterpreter payloads, communicates with C2 servers using the user-agent string "bumblebee", and includes IoCs (sample SHA256 and C2 45.147.229.23:443).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
