Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2
- Host form
- 24 IP / 0 hostnames
Bumblebee is a Windows malware loader first observed in 2022 and primarily used to establish access and deliver follow-on payloads.
Profile source: Mallory opens in a new tabBumblebee
Bumblebee is a Windows malware loader first observed in 2022 and primarily used to establish access and deliver follow-on payloads. It has been distributed in phishing and thread-hijacking campaigns using malicious links or attachments, including disk-image files, archives, shortcut files, OneNote documents, and file-sharing-service lures. Observed distribution activity has been associated with TA578 and EXOTIC LILY. Bumblebee infections have been followed by post-exploitation tooling including Cobalt Strike and Brute Ratel, and may precede ransomware activity.
Bumblebee is commonly delivered as a DLL executed through legitimate Windows utilities. It uses packing, encryption, obfuscation, and extensive anti-analysis logic, including checks for virtualized environments, sandbox artifacts, analyst tools, hardware characteristics, and user activity. It can identify usernames, running processes, system and security software information, and registry data. Its command-and-control communications have evolved from HTTP to WebSockets and may use encrypted channels.
The loader supports download-and-execute operations, shell command execution, plugin loading, shellcode injection, DLL injection, persistence, and removal. It can create Visual Basic scripts for persistence and bypass User Account Control to deploy elevated post-exploitation tools. Bumblebee configurations may contain campaign mission identifiers, command-and-control entries including decoys, and RC4-encrypted configuration data. The malware has been frequently protected with the Forest crypter.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
2022-05-18 (WEDNESDAY) ISC DIARY: EXOTIC LILY --> BUMBLEBEE --> COBALT STRIKE ... REFERENCE: This is the pcap and malware for an ISC diary on 2022-05-19: Bumblebee Malware from TransferXL URLs
Cynetβs Threat Research and Intelligence team recently discovered a new malware campaign called BumbleBee. From our initial analysis, BumbleBee is a custom new loader that is used by different IAB groups.
Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
A newly discovered malware loader called Bumblebee is likely the latest development of the Conti syndicate, designed to replace the BazarLoader backdoor used to deliver ransomware payloads.
Intel 471 researchers have noticed that the Conti group appears to have dropped BazarLoader in favor of a new malware called Bumblebee... Google stating that Bumblebee has been used by an access broker with ties to Conti.
The noteable spike of campaigns involving malicious shortcuts (LNK files) conducted by both APT groups and advanced cybercriminals was detected in April-May this year β Bumblebee Loader and UAC-0010 (Armageddon) targeting EU Countries.
Thus far, Raspberry Robin has been observed distributing payloads linked to FIN11, Clop Gang, BumbleBee, IcedID, and TrueBot on compromised networks.
Actors issued these commands via a web shell we call BumbleBee that had been installed on the Exchange server, which we will discuss in detail in a future blog.
βTA580 used it to drop Bumblebee, why donβt we have a VHD chain?β
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022.
Cyjax, highlighting the use of SEO poisoning to redirect users searching for software programs from companies like SonicWall, Hanwha Vision, and Pulse Secure (now Ivanti Secure Access) on Bing to fake sites and trick them into downloading MSI installers that deploy the Bumblebee loader.
Exploited software
MITRE ATT&CK
Reporting
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.