Malware.View on attack.mitre.org
Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1008 Fallback Channels |
Bumblebee can use backup C2 servers if the primary server fails. |
| T1012 Query Registry |
Bumblebee can check the Registry for specific keys. |
| T1027 Obfuscated Files or Information |
Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1033 System Owner/User Discovery |
Bumblebee has the ability to identify the user name. |
| T1036.005 Match Legitimate Resource Name or Location |
Bumblebee has named component DLLs "RapportGP.dll" to match those used by the security company Trusteer. |
| T1041 Exfiltration Over C2 Channel |
Bumblebee can send collected data in JSON format to C2. |
| T1047 Windows Management Instrumentation |
Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1053.005 Scheduled Task |
Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task. |
| T1055 Process Injection |
Bumblebee can inject code into multiple processes on infected endpoints. |
| T1055.001 Dynamic-link Library Injection |
The Bumblebee loader can support the `Dij` command which gives it the ability to inject DLLs into the memory of other processes. |
| T1055.004 Asynchronous Procedure Call |
Bumblebee can use asynchronous procedure call (APC) injection to execute commands received from C2. |
| T1057 Process Discovery |
Bumblebee can identify processes associated with analytical tools. |
| T1059.001 PowerShell |
Bumblebee can use PowerShell for execution. |
| T1059.003 Windows Command Shell |
Bumblebee can use `cmd.exe` to drop and run files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.