Bumblebee

S1039

Malware.View on attack.mitre.org

About this malware

Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.

Techniques used39

Procedure examples39

TechniqueProcedure example
T1005
Data from Local System

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1008
Fallback Channels

Bumblebee can use backup C2 servers if the primary server fails.

T1012
Query Registry

Bumblebee can check the Registry for specific keys.

T1027
Obfuscated Files or Information

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1033
System Owner/User Discovery

Bumblebee has the ability to identify the user name.

T1036.005
Match Legitimate Resource Name or Location

Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer.

T1041
Exfiltration Over C2 Channel

Bumblebee can send collected data in JSON format to C2.

T1047
Windows Management Instrumentation

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1053.005
Scheduled Task

Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task.

T1055
Process Injection

Bumblebee can inject code into multiple processes on infected endpoints.

T1055.001
Dynamic-link Library Injection

The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes.

T1055.004
Asynchronous Procedure Call

Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2.

T1057
Process Discovery

Bumblebee can identify processes associated with analytical tools.

T1059.001
PowerShell

Bumblebee can use PowerShell for execution.

T1059.003
Windows Command Shell

Bumblebee can use `cmd.exe` to drop and run files.

View all 39 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. Google EXOTIC LILY March 2022 Open source
    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.
  2. Proofpoint Bumblebee April 2022 Open source
    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.
  3. Symantec Bumblebee June 2022 Open source
    Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.