Description
Bumblebee is an alternate detection name for the BumbleBee malware loader, a delivery tool that emerged in 2022 and installs heavier payloads on infected systems. Its operators distribute it through phishing emails with striped archive attachments, and it commonly fetches remote access trojans, information stealers, and command and control beacons for ransomware operators. The loader's operators rewrite it regularly to defeat analysis and detection.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
BumbleBeeBumbleBeeLoader
MITRE ATT&CK techniques
39 techniques across 8 tactics.
TA0002 Execution
TA0004 Privilege Escalation
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1055Process Injection
- T1055Process Injection
- T1070Indicator Removal
- T1070.004File Deletion
- T1140Deobfuscate/Decode Files or Information
- T1218System Binary Proxy Execution
- T1497Virtualization/Sandbox Evasion
- T1497Virtualization/Sandbox Evasion
- T1622Debugger Evasion
TA0007 Discovery
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
Associated groups
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.BumbleBee.A.3D6472FE |
| DeepScan:Generic.BumbleBee.A.3FF3AFA2 |
| Document-Office.Downloader.Bumblebee |
| Document-PDF.Trojan.Bumblebee |
| Document-Word.Trojan.Bumblebee |
| Gen:Variant.BumbleBee.2 |
| Gen:Variant.Bumblebee.5 |
| Gen:Variant.Ransom.BumbleBee.121 |
| Gen:Variant.Ransom.BumbleBee.153 |
| Gen:Variant.Ransom.BumbleBee.155 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Bumblebee.Generic.Get traffic detected |
