Skip to content

Bumblebee

BumbleBee is a Windows malware family best characterized as a modular loader used to establish initial access and deliver follow-on payloads in enterprise intrusions.

Profile source: Mallory opens in a new tab

Bumblebee

Family profile

BumbleBee is a Windows malware family best characterized as a modular loader used to establish initial access and deliver follow-on payloads in enterprise intrusions. It emerged as a prominent replacement in the loader ecosystem after disruptions to earlier crimeware families and has been associated with financially motivated operations that later deploy tools such as AdaptixC2 and ransomware including Akira. BumbleBee has also been linked to broader cybercrime infrastructure and was among the loaders targeted by international law-enforcement action in 2024.

The malware is commonly delivered through trojanized software installers and disk-image style container formats, including MSI, ISO, and LNK-based infection chains. Observed campaigns have used SEO poisoning and fake software download pages to lure victims searching for enterprise IT tools, as well as compromised software distribution. Execution frequently relies on DLL side-loading or proxying through legitimate signed Windows or application binaries. In some campaigns, operators deliberately target software likely to be executed by administrators, increasing the chance of privileged initial access.

BumbleBee is designed for stealth and staged execution. Reported samples use packing and obfuscation, anti-analysis checks, process-based tool detection, registry checks, geofencing, and dynamic API resolution. It can identify analysis environments and security tooling, and some variants use domain generation algorithms for command-and-control discovery. The malware supports modular payload retrieval and has been observed downloading additional components after initial execution.

Post-compromise behavior attributed to BumbleBee includes process injection, including APC-based injection techniques, and use as a launch point for persistent command-and-control beacons. In intrusion reporting, BumbleBee-enabled access has preceded reconnaissance, credential theft, lateral movement, persistence through remote administration software, and large-scale data exfiltration before ransomware deployment. Its operational role is therefore primarily as an access and delivery platform rather than a standalone end-stage payload.

BumbleBee targets Windows environments and has been observed in enterprise compromises affecting organizations using administrative and infrastructure management tooling. High-confidence reporting supports its role as a loader in financially motivated intrusion chains rather than as a banking trojan or pure infostealer.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Initial Access
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Reported operators

Threat actors

9 named in public reporting
TA579

Starting in March 2022, Proofpoint observed campaigns delivering a new downloader called Bumblebee. ... Bumblebee's objective is to download and execute additional payloads. Proofpoint researchers observed Bumblebee dropping Cobalt Strike, shellcode, Sliver and Meterpreter.

TA578

Starting in March 2022, Proofpoint observed campaigns delivering a new downloader called Bumblebee. ... Bumblebee's objective is to download and execute additional payloads. Proofpoint researchers observed Bumblebee dropping Cobalt Strike, shellcode, Sliver and Meterpreter.

xHunt

This investigation resulted in the discovery of two new backdoors called TriFive and Snugy, which we discussed in a prior blog, as well as a new webshell that we call BumbleBee... The actor used the BumbleBee webshell to upload and download files to and from the compromised Exchange server, but more importantly, to run commands that the actor used to discover additional systems and to move laterally to other servers on the network.

TA580

“TA580 used it to drop Bumblebee, why don’t we have a VHD chain?”

Storm-0249

Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

Conti

"...a supply chain attack that distributed a trojanized installer to drop the Bumblebee malware loader on users' machines."

WIZARD SPIDER

In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022.

EXOTIC LILY

In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022.

Storm 2561

Cyjax, highlighting the use of SEO poisoning to redirect users searching for software programs from companies like SonicWall, Hanwha Vision, and Pulse Secure (now Ivanti Secure Access) on Bing to fake sites and trick them into downloading MSI installers that deploy the Bumblebee loader.

MITRE ATT&CK

Bumblebee in ATT&CK

89 distinct techniques

Techniques

89 techniques
T1204.002 Malicious File T1566 Phishing T1036 Masquerading T1195 Supply Chain Compromise T1012 Query Registry T1518.001 Security Software Discovery T1082 System Information Discovery T1574.001 DLL T1189 Drive-by Compromise T1568.002 Domain Generation Algorithms T1027.002 Software Packing T1056.001 Keylogging T1071.004 DNS T1059.003 Windows Command Shell T1105 Ingress Tool Transfer T1027 Obfuscated Files or Information T1071.001 Web Protocols T1608.006 SEO Poisoning T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1071 Application Layer Protocol T1055 Process Injection T1583 Acquire Infrastructure T1055.004 Asynchronous Procedure Call T1622 Debugger Evasion T1112 Modify Registry T1027.007 Dynamic API Resolution T1497.001 System Checks T1055.001 Dynamic-link Library Injection T1106 Native API T1560 Archive Collected Data T1033 System Owner/User Discovery T1140 Deobfuscate/Decode Files or Information T1547 Boot or Logon Autostart Execution T1586 Compromise Accounts T1566.001 Spearphishing Attachment T1059.005 Visual Basic T1218.011 Rundll32 T1573 Encrypted Channel T1497 Virtualization/Sandbox Evasion T1566.002 Spearphishing Link T1566.003 Spearphishing via Service T1053.005 Scheduled Task T1047 Windows Management Instrumentation T1132 Data Encoding T1057 Process Discovery T1005 Data from Local System T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1036.005 Match Legitimate Resource Name or Location T1070.004 File Deletion T1003 OS Credential Dumping T1204 User Execution T1547.009 Shortcut Modification T1505.003 Web Shell T1572 Protocol Tunneling T1213 Data from Information Repositories T1021.002 SMB/Windows Admin Shares T1124 System Time Discovery T1083 File and Directory Discovery T1003.001 LSASS Memory T1570 Lateral Tool Transfer T1135 Network Share Discovery T1016 System Network Configuration Discovery T1021.001 Remote Desktop Protocol T1046 Network Service Discovery T1018 Remote System Discovery T1562 Impair Defenses T1553.002 Code Signing T1569.002 Service Execution T1583.001 Domains T1588.003 Code Signing Certificates T1614.001 System Language Discovery T1548.002 Bypass User Account Control T1027.013 Encrypted/Encoded File T1129 Shared Modules T1555 Credentials from Password Stores T1053 Scheduled Task/Job T1574 Hijack Execution Flow T1553.005 Mark-of-the-Web Bypass T1008 Fallback Channels T1102 Web Service T1132.001 Standard Encoding T1497.003 Time Based Checks T1204.001 Malicious Link T1559.001 Component Object Model T1573.001 Symmetric Cryptography T1218.008 Odbcconf T1195.002 Compromise Software Supply Chain

Reporting

Research mentioning Bumblebee

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 24
Security Online Info

ACR Stealer Spreads Through ClickFix Lures

Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Jul 18
Bleeping Computer

Microsoft warns of surge in ACR Stealer attacks on customers

Jul 17
Scworld

ACR Stealer exploits user interaction to steal sensitive data | brief | SC Media

Jul 17
The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

Jul 16
Malware News

ACR Stealer: Two observed intrusion chains amid increased threat activity - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.