Skip to content

Bumblebee

Bumblebee is a Windows malware loader that emerged in 2022 and became a prominent initial-access and malware-delivery platform in cybercrime operations.

Profile source: Mallory opens in a new tab

Bumblebee

Family profile

Bumblebee is a Windows malware loader that emerged in 2022 and became a prominent initial-access and malware-delivery platform in cybercrime operations. It has been associated with intrusion activity linked to actors such as EXOTIC LILY and TA578, and has been observed in campaigns that led to follow-on deployment of post-exploitation frameworks including Cobalt Strike and Brute Ratel. Reporting has also noted code and ecosystem relationships connecting Bumblebee to actors tied to TrickBot, Conti, Quantum, and possibly Ramnit-related development.

Bumblebee is typically delivered through socially engineered infection chains using phishing or spearphishing lures, often via legitimate file-sharing services or thread-hijacked email conversations. Observed delivery artifacts have included disk-image formats such as ISO and VHD, malicious shortcut files, OneNote documents, and PowerShell-based loaders. In multiple campaigns, user interaction with a mounted image or shortcut triggered execution of a Bumblebee DLL through native Windows utilities, after which the malware established command-and-control communications and awaited tasking.

Its primary role is to stage additional malicious capability on compromised hosts. Documented command support includes shellcode injection, DLL injection, download-and-execute, shell command execution, plugin loading, uninstall, and persistence establishment. Bumblebee has also been observed creating Visual Basic script-based persistence, identifying the current username, and performing extensive environment checks before or during execution. Anti-analysis and defense-evasion behavior is a defining characteristic: samples have checked for debuggers, malware-analysis tools, virtualization artifacts, sandbox indicators, hardware anomalies, and lack of user activity. Some variants can identify analytical tools by enumerating running processes, and the malware has been reported to bypass Windows User Account Control to deploy post-exploitation tooling with elevated privileges.

Bumblebee has evolved over time in both communications and internal protections. Early samples used HTTP for command-and-control, while later versions adopted WebSockets. Samples are frequently packed, encrypted, or obfuscated, and configuration data may be stored in plaintext or encrypted with RC4. Extracted configurations have included mission identifiers and command-and-control lists, enabling clustering of operational activity across campaigns. Research on sample clustering indicates that a small number of operators, and at times possibly a single dominant actor, accounted for much of the observed Bumblebee activity during parts of 2023.

The malware has figured prominently enough in the criminal ecosystem to be named among major droppers disrupted during Operation Endgame in 2024. Its operational significance stems from its role as a flexible loader used to convert phishing-driven access into broader compromise, credentialed post-exploitation, lateral movement tooling, and, in some cases, ransomware deployment.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 7, 2026
Feed role
C2
Host form
0 IP / 100 hostnames

Leading locations

  • IE3
  • US2
  • DE1

Leading providers

  • Amazon.com, Inc.5
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 6

Samples

Recent associated samples

Reported operators

Threat actors

12 named in public reporting
EXOTIC LILY

2022-05-18 (WEDNESDAY) ISC DIARY: EXOTIC LILY --> BUMBLEBEE --> COBALT STRIKE ... REFERENCE: This is the pcap and malware for an ISC diary on 2022-05-19: Bumblebee Malware from TransferXL URLs

TA578

TA578 also appears to be pushing ISO files for Bumblebee malware through thread-hijacked emails.

WIZARD SPIDER

Cynet’s Threat Research and Intelligence team recently discovered a new malware campaign called BumbleBee. From our initial analysis, BumbleBee is a custom new loader that is used by different IAB groups.

Storm-0249

Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

TA579

A newly discovered malware loader called Bumblebee is likely the latest development of the Conti syndicate, designed to replace the BazarLoader backdoor used to deliver ransomware payloads.

Conti

Intel 471 researchers have noticed that the Conti group appears to have dropped BazarLoader in favor of a new malware called Bumblebee... Google stating that Bumblebee has been used by an access broker with ties to Conti.

Gamaredon Group

The noteable spike of campaigns involving malicious shortcuts (LNK files) conducted by both APT groups and advanced cybercriminals was detected in April-May this year – Bumblebee Loader and UAC-0010 (Armageddon) targeting EU Countries.

Conti group

Deep Instinct’s Threat Research Lab recently noticed a new strain of a JavaScript-based dropper that is delivering Bumblebee and IcedID. Bumblebee is a malware loader first discovered in March 2022.

FIN11

Thus far, Raspberry Robin has been observed distributing payloads linked to FIN11, Clop Gang, BumbleBee, IcedID, and TrueBot on compromised networks.

xHunt

Actors issued these commands via a web shell we call BumbleBee that had been installed on the Exchange server, which we will discuss in detail in a future blog.

TA580

“TA580 used it to drop Bumblebee, why don’t we have a VHD chain?”

Storm 2561

Cyjax, highlighting the use of SEO poisoning to redirect users searching for software programs from companies like SonicWall, Hanwha Vision, and Pulse Secure (now Ivanti Secure Access) on Bing to fake sites and trick them into downloading MSI installers that deploy the Bumblebee loader.

Exploited software

Vulnerabilities linked to Bumblebee

1 CVEs

MITRE ATT&CK

Bumblebee in ATT&CK

119 distinct techniques

Techniques

119 techniques
T1055 Process Injection T1027 Obfuscated Files or Information T1027.002 Software Packing T1497 Virtualization/Sandbox Evasion T1140 Deobfuscate/Decode Files or Information T1518.001 Security Software Discovery T1059.005 Visual Basic T1057 Process Discovery T1568.002 Domain Generation Algorithms T1082 System Information Discovery T1548.002 Bypass User Account Control T1547.001 Registry Run Keys / Startup Folder T1033 System Owner/User Discovery T1071 Application Layer Protocol T1566.001 Spearphishing Attachment T1497.001 System Checks T1547 Boot or Logon Autostart Execution T1560 Archive Collected Data T1586.002 Email Accounts T1497.002 User Activity Based Checks T1218.011 Rundll32 T1055.001 Dynamic-link Library Injection T1204.002 Malicious File T1027.013 Encrypted/Encoded File T1036 Masquerading T1566.002 Spearphishing Link T1059.001 PowerShell T1105 Ingress Tool Transfer T1059 Command and Scripting Interpreter T1620 Reflective Code Loading T1204.001 Malicious Link T1566 Phishing T1548.003 Sudo and Sudo Caching T1496 Resource Hijacking T1204 User Execution T1087 Account Discovery T1056.001 Keylogging T1552 Unsecured Credentials T1059.003 Windows Command Shell T1018 Remote System Discovery T1037.001 Logon Script (Windows) T1070.004 File Deletion T1132.001 Standard Encoding T1547.009 Shortcut Modification T1047 Windows Management Instrumentation T1587.001 Malware T1012 Query Registry T1583 Acquire Infrastructure T1055.004 Asynchronous Procedure Call T1021 Remote Services T1053.005 Scheduled Task T1071.001 Web Protocols T1480.001 Environmental Keying T1564.001 Hidden Files and Directories T1560.001 Archive via Utility T1016 System Network Configuration Discovery T1573.001 Symmetric Cryptography T1592 Gather Victim Host Information T1053 Scheduled Task/Job T1090 Proxy T1055.003 Thread Execution Hijacking T1129 Shared Modules T1559.001 Component Object Model T1059.007 JavaScript T1218.007 Msiexec T1553.005 Mark-of-the-Web Bypass T1573 Encrypted Channel T1001 Data Obfuscation T1586.001 Social Media Accounts T1218.001 Compiled HTML File T1218 System Binary Proxy Execution T1518 Software Discovery T1574.006 Dynamic Linker Hijacking T1562 Impair Defenses T1027.006 HTML Smuggling T1574 Hijack Execution Flow T1566.003 Spearphishing via Service T1562.001 Disable or Modify Tools T1505.003 Web Shell T1106 Native API T1134 Access Token Manipulation T1055.012 Process Hollowing T1548 Abuse Elevation Control Mechanism T1090.003 Multi-hop Proxy T1543 Create or Modify System Process T1195 Supply Chain Compromise T1574.001 DLL T1189 Drive-by Compromise T1071.004 DNS T1608.006 SEO Poisoning T1568 Dynamic Resolution T1622 Debugger Evasion T1112 Modify Registry T1027.007 Dynamic API Resolution T1586 Compromise Accounts T1132 Data Encoding T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1036.005 Match Legitimate Resource Name or Location T1003 OS Credential Dumping T1572 Protocol Tunneling T1213 Data from Information Repositories T1021.002 SMB/Windows Admin Shares T1124 System Time Discovery T1083 File and Directory Discovery T1003.001 LSASS Memory T1570 Lateral Tool Transfer T1135 Network Share Discovery T1021.001 Remote Desktop Protocol T1046 Network Service Discovery T1553.002 Code Signing T1569.002 Service Execution T1583.001 Domains T1588.003 Code Signing Certificates T1614.001 System Language Discovery T1555 Credentials from Password Stores T1008 Fallback Channels T1102 Web Service T1497.003 Time Based Checks

Reporting

Research mentioning Bumblebee

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 24
Security Online Info

ACR Stealer Spreads Through ClickFix Lures

Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Jul 18
Bleeping Computer

Microsoft warns of surge in ACR Stealer attacks on customers

Jul 17
Scworld

ACR Stealer exploits user interaction to steal sensitive data | brief | SC Media

Jul 17
The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

Jul 16
Malware News

ACR Stealer: Two observed intrusion chains amid increased threat activity - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.