logo

Adventures in the land of BumbleBee

ID: 7bc450e2-c486-505b-939b-024a4e78919b

STIX ID: report--7bc450e2-c486-505b-939b-024a4e78919b

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2022-04-29

Date Updated: 2026-04-27

Author: Global Threat Intelligence

...
...

BUMBLEBEE is a actively developed malicious loader used in multiple distribution methods (ISO attachments, OneDrive links, email thread hijacking) that implements anti-analysis measures, RC4-encrypted HTTPS C2 communication, process injection and persistence via scheduled tasks and VBS, and has been observed delivering Cobalt Strike, Meterpreter, Sliver and Bokbot payloads; the report includes detailed technical behavior, task types, group tags and a large set of IP-based IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.