Cybereason. (2022, August 17). Bumblebee Loader – The High Road to Enterprise Domain Control. Retrieved August 29, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBumblebee | Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1018 Remote System Discovery |
ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| T1021.001 Remote Desktop Protocol |
MalwareCobalt Strike | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1055 Process Injection |
MalwareBumblebee | Bumblebee can inject code into multiple processes on infected endpoints. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1204.001 Malicious Link |
MalwareBumblebee | Bumblebee has relied upon a user downloading a file from a OneDrive link for execution. |
| T1204.002 Malicious File |
MalwareBumblebee | Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs. |
| T1218.008 Odbcconf |
MalwareBumblebee | Bumblebee can use `odbcconf.exe` to run DLLs on targeted hosts. |
| T1548.002 Bypass User Account Control |
MalwareBumblebee | Bumblebee has the ability to bypass UAC to deploy post exploitation tools with elevated privileges. |
| T1560 Archive Collected Data |
MalwareBumblebee | Bumblebee can compress data stolen from the Registry and volume shadow copies prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
MalwareBumblebee | Bumblebee has gained execution through luring users into opening malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareBumblebee | Bumblebee has been spread through e-mail campaigns with malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.