Bumblebee

MITRE ATT&CK: S1039 View on attack.mitre.org

Aliases: COLDTRAIN, SHELLSTING, Shindig, Bumblebee

First seen
2022-03-01 00:00:00
Malware type
loader, dropper
Family
Malware family
Operating systems
windows
Related IoCs
2764 (2251 malicious)
Last IoC activity
2026-09-02 02:36:11
Profile updated
2026-07-07 13:01:13

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.

Recent IoC activity

2,251 malicious indicators in Maltiverse are attributed to Bumblebee (S1039). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname hx0hysyg.life 2026-09-03 1
hostname 6vfmbabg9pc9.live 2026-09-03 1
hostname hkk3112645hz.live 2026-09-03 1
hostname wc87pfwqvbx.life 2026-09-03 1
hostname 2g6py8d93tm.life 2026-09-03 1
hostname secops.vunetsystems.com 2026-09-03 1
hostname knof8y1kufn.life 2026-09-03 1
hostname 3wea9rl1rgeg.live 2026-09-03 1
hostname rjql4nicl6bg.live 2026-09-03 1
hostname server.instahosting.in 2026-09-03 1
hostname 42grunsnoe9w.live 2026-09-03 1
hostname 0tia8g2yvvo.life 2026-09-03 1
hostname ilp3urzo9kag.live 2026-09-03 1
hostname 216-48-179-60.cprapid.com 2026-09-03 1
hostname e2e-73-176.ssdcloudindia.net 2026-09-03 1
hostname e2e-73-172.ssdcloudindia.net 2026-09-03 1
hostname yan95akxgqt.life 2026-09-03 1
hostname 4kqz7kqt2.life 2026-09-03 1
hostname 40vzdof7rw3k.live 2026-09-03 1
hostname 6ijcq51cepr6.live 2026-09-03 1

Detection coverage

  • 7 YARA rules
  • 818 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Checks (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Odbcconf (attack-pattern)
  • Data from Local System (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Asynchronous Procedure Call (attack-pattern)
  • Visual Basic (attack-pattern)
  • Web Service (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Rundll32 (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Process Injection (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

  • EXOTIC LILY (threat-actor)
  • TA578 (threat-actor)
  • Bumblebee Distribution Campaigns 2023-24 (campaign)

Exploited vulnerabilities

  • CVE-2021-40444 (vulnerability)

Detection rules

  • MALPEDIA_Win_Bumblebee_Auto (yara-rule)
  • CHECK_POINT_Malware_Bumblebee_Packed (yara-rule)
  • SEKOIA_Bumblebee_Loader (yara-rule)
  • SEKOIA_Loader_Win_Bumblebee (yara-rule)
  • CAPE_Bumblebee (yara-rule)
  • CAPE_Bumblebeeshellcode_1 (yara-rule)
  • CAPE_Bumblebee2024 (yara-rule)

Reports & references

  • blog.google — Exposing Initial Access Broker Ties Conti (report)
  • proofpoint.com — Bumblebee Is Still Transforming (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
  • research.nccgroup.com — Adventures In The Land Of Bumblebee A New Malicious Loader (report)
  • Palo Alto Unit 42 — Bumblebee Malware Projector Libra (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • deepinstinct.com — Pindos New Javascript Dropper Delivering Bumblebee And Icedid (report)
  • thedfirreport.com — From Bing Search To Ransomware Bumblebee And Adaptixc2 Deliver Akira 2 (report)
  • thedfirreport.com — From Bing Search To Ransomware Bumblebee And Adaptixc2 Deliver Akira (report)
  • securityintelligence.com — Trickbot Group Systematically Attacking Ukraine (report)
  • resecurity.com — Shortcut Based Lnk Attacks Delivering Malicious Code On The Rise (report)
  • youtube.com — Watch (report)
  • team-cymru.com — Bablosoft Lowering The Barrier Of Entry For Malicious Actors (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bumblebee (report)
  • blog.cyble.com — Bumblebee Returns With New Infection Technique (report)
  • blog.gigamon.com — Rendering Threats A Network Perspective (report)
  • lumu.io — Bumblebee Malware Loader Spotlight (report)
  • blog.cyble.com — Bumblebee Loader On The Rise (report)
  • youtube.com — Watch (report)
  • bin.re — The Dga Of Bumblebee (report)

External references