ATT&CKReferencesCybereason Bumblebee August 2022

Cybereason Bumblebee August 2022

Cybereason. (2022, August 17). Bumblebee Loader – The High Road to Enterprise Domain Control. Retrieved August 29, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBumblebee

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1018
Remote System Discovery
ToolAdFind

AdFind has the ability to query Active Directory for computers.

T1021.001
Remote Desktop Protocol
MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1055
Process Injection
MalwareBumblebee

Bumblebee can inject code into multiple processes on infected endpoints.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1204.001
Malicious Link
MalwareBumblebee

Bumblebee has relied upon a user downloading a file from a OneDrive link for execution.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1218.008
Odbcconf
MalwareBumblebee

Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts.

T1548.002
Bypass User Account Control
MalwareBumblebee

Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges.

T1560
Archive Collected Data
MalwareBumblebee

Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1566.002
Spearphishing Link
MalwareBumblebee

Bumblebee has been spread through e-mail campaigns with malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.