Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareBumblebee | Bumblebee can use backup C2 servers if the primary server fails. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1053.005 Scheduled Task |
MalwareBumblebee | Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task. |
| T1055.001 Dynamic-link Library Injection |
MalwareBumblebee | The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.004 Asynchronous Procedure Call |
MalwareBumblebee | Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2. |
| T1057 Process Discovery |
MalwareBumblebee | Bumblebee can identify processes associated with analytical tools. |
| T1059.003 Windows Command Shell |
MalwareBumblebee | Bumblebee can use `cmd.exe` to drop and run files. |
| T1059.005 Visual Basic |
MalwareBumblebee | Bumblebee can create a Visual Basic script to enable persistence. |
| T1070.004 File Deletion |
MalwareBumblebee | Bumblebee can uninstall its loader through the use of a `Sdl` command. |
| T1082 System Information Discovery |
MalwareBumblebee | Bumblebee can enumerate the OS version and domain on a targeted system. |
| T1102 Web Service |
MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1106 Native API |
MalwareBumblebee | Bumblebee can use multiple Native APIs. |
| T1132.001 Standard Encoding |
MalwareBumblebee | Bumblebee has the ability to base64 encode C2 server responses. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBumblebee | Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts. |
| T1204.001 Malicious Link |
MalwareBumblebee | Bumblebee has relied upon a user downloading a file from a OneDrive link for execution. |
| T1204.002 Malicious File |
GroupEXOTIC LILY | EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1218.011 Rundll32 |
MalwareBumblebee | Bumblebee has used `rundll32` for execution of the loader component. |
| T1497 Virtualization/Sandbox Evasion |
MalwareBumblebee | Bumblebee has the ability to perform anti-virtualization checks. |
| T1497.003 Time Based Checks |
MalwareBumblebee | Bumblebee has the ability to set a hardcoded and randomized sleep interval. |
| T1518.001 Security Software Discovery |
MalwareBumblebee | Bumblebee can identify specific analytical tools based on running processes. |
| T1559.001 Component Object Model |
MalwareBumblebee | Bumblebee can use a COM object to execute queries to gather system information. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.001 Spearphishing Attachment |
GroupEXOTIC LILY | EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments. |
| T1566.002 Spearphishing Link |
MalwareBumblebee | Bumblebee has been spread through e-mail campaigns with malicious links. |
| T1573.001 Symmetric Cryptography |
MalwareBumblebee | Bumblebee can encrypt C2 requests and responses with RC4 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.