logo

Technical Analysis of Bumblebee Malware Loader

ID: 70f3e97f-e89f-5442-9dde-230882d71d66

STIX ID: report--70f3e97f-e89f-5442-9dde-230882d71d66

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2022-08-04

Date Updated: 2026-04-27

...
...

Bumblebee is a sophisticated malware loader delivered via malicious ISO attachments (often in thread‑hijacked emails) that unpacks an embedded DLL, installs in-line hooks on ntdll functions to hollow gdiplus.dll with the final payload, and performs extensive anti‑VM, persistence, token manipulation, and code‑injection techniques; it has been observed delivering Cobalt Strike and Meterpreter payloads, communicates with C2 servers using the user-agent string "bumblebee", and includes IoCs (sample SHA256 and C2 45.147.229.23:443).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.