Netskope Threat Labs

Bumblebee

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Bumblebee is an alternate detection name for the BumbleBee malware loader, a delivery tool that emerged in 2022 and installs heavier payloads on infected systems. Its operators distribute it through phishing emails with striped archive attachments, and it commonly fetches remote access trojans, information stealers, and command and control beacons for ransomware operators. The loader's operators rewrite it regularly to defeat analysis and detection.

First seen
May 2022
Last seen
October 2026
BumbleBeeBumbleBeeLoader

39 techniques across 8 tactics.

TA0001 Initial Access

TA0002 Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

TA0009 Collection

  • T1005Data from Local System
  • T1560Archive Collected Data

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
DeepScan:Generic.BumbleBee.A.3D6472FE
DeepScan:Generic.BumbleBee.A.3FF3AFA2
Document-Office.Downloader.Bumblebee
Document-PDF.Trojan.Bumblebee
Document-Word.Trojan.Bumblebee
Gen:Variant.BumbleBee.2
Gen:Variant.Bumblebee.5
Gen:Variant.Ransom.BumbleBee.121
Gen:Variant.Ransom.BumbleBee.153
Gen:Variant.Ransom.BumbleBee.155