ATT&CKReferencesProofpoint Bumblebee April 2022

Proofpoint Bumblebee April 2022

Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareBumblebee

Bumblebee can use backup C2 servers if the primary server fails.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1053.005
Scheduled Task
MalwareBumblebee

Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task.

T1055.001
Dynamic-link Library Injection
MalwareBumblebee

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.004
Asynchronous Procedure Call
MalwareBumblebee

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

T1057
Process Discovery
MalwareBumblebee

Bumblebee can identify processes associated with analytical tools.

T1059.003
Windows Command Shell
MalwareBumblebee

Bumblebee can use `cmd.exe` to drop and run files.

T1059.005
Visual Basic
MalwareBumblebee

Bumblebee can create a Visual Basic script to enable persistence.

T1070.004
File Deletion
MalwareBumblebee

Bumblebee can uninstall its loader through the use of a `Sdl` command.

T1082
System Information Discovery
MalwareBumblebee

Bumblebee can enumerate the OS version and domain on a targeted system.

T1102
Web Service
MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

T1105
Ingress Tool Transfer
MalwareBumblebee

Bumblebee can download and execute additional payloads including through the use of a `Dex` command.

T1106
Native API
MalwareBumblebee

Bumblebee can use multiple Native APIs.

T1132.001
Standard Encoding
MalwareBumblebee

Bumblebee has the ability to base64 encode C2 server responses.

T1140
Deobfuscate/Decode Files or Information
MalwareBumblebee

Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts.

T1204.001
Malicious Link
MalwareBumblebee

Bumblebee has relied upon a user downloading a file from a OneDrive link for execution.

T1204.002
Malicious File
GroupEXOTIC LILY

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1218.011
Rundll32
MalwareBumblebee

Bumblebee has used `rundll32` for execution of the loader component.

T1497
Virtualization/Sandbox Evasion
MalwareBumblebee

Bumblebee has the ability to perform anti-virtualization checks.

T1497.003
Time Based Checks
MalwareBumblebee

Bumblebee has the ability to set a hardcoded and randomized sleep interval.

T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1559.001
Component Object Model
MalwareBumblebee

Bumblebee can use a COM object to execute queries to gather system information.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1566.001
Spearphishing Attachment
GroupEXOTIC LILY

EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments.

T1566.002
Spearphishing Link
MalwareBumblebee

Bumblebee has been spread through e-mail campaigns with malicious links.

T1573.001
Symmetric Cryptography
MalwareBumblebee

Bumblebee can encrypt C2 requests and responses with RC4

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.