ATT&CKReferencesMedium Ali Salem Bumblebee April 2022

Medium Ali Salem Bumblebee April 2022

Salem, A. (2022, April 27). The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection. Retrieved September 2, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareBumblebee

Bumblebee can check the Registry for specific keys.

T1027
Obfuscated Files or Information
MalwareBumblebee

Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions.

T1036.005
Match Legitimate Resource Name or Location
MalwareBumblebee

Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer.

T1057
Process Discovery
MalwareBumblebee

Bumblebee can identify processes associated with analytical tools.

T1059.001
PowerShell
MalwareBumblebee

Bumblebee can use PowerShell for execution.

T1106
Native API
MalwareBumblebee

Bumblebee can use multiple Native APIs.

T1129
Shared Modules
MalwareBumblebee

Bumblebee can use `LoadLibrary` to attempt to execute GdiPlus.dll.

T1140
Deobfuscate/Decode Files or Information
MalwareBumblebee

Bumblebee can deobfuscate C2 server responses and unpack its code on targeted hosts.

T1204.002
Malicious File
MalwareBumblebee

Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs.

T1497.001
System Checks
MalwareBumblebee

Bumblebee has the ability to search for designated file paths and Registry keys that indicate a virtualized environment from multiple products.

T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1566.001
Spearphishing Attachment
MalwareBumblebee

Bumblebee has gained execution through luring users into opening malicious attachments.

T1622
Debugger Evasion
MalwareBumblebee

Bumblebee can search for tools used in static analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.