Bumblebee Malware Returns with New Tricks, Targeting U.S. Businesses
ID: c2c805c4-cc69-53e2-a9b6-d5e8d8be72ca
STIX ID: report--c2c805c4-cc69-53e2-a9b6-d5e8d8be72ca
Feed Name: The Hacker News
Proofpoint and other vendors observed the Bumblebee loader reappearing in February 2024 as part of voicemail-themed phishing that uses macro-enabled Word documents to launch PowerShell and retrieve the loader; the report also highlights resurfacing and enhanced variants of QakBot, ZLoader, and PikaBot using MSI/CAB chains, strengthened encryption, VM detection, and diverse delivery methods, indicating active, evolving criminal campaigns that enable follow-on ransomware and credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
