Bumblebee
MITRE ATT&CK: S1039 View on attack.mitre.org
Aliases: COLDTRAIN, SHELLSTING, Shindig, Bumblebee
- First seen
- 2022-03-01 00:00:00
- Malware type
- loader, dropper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2764 (2251 malicious)
- Last IoC activity
- 2026-09-02 02:36:11
- Profile updated
- 2026-07-07 13:01:13
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.
Recent IoC activity
2,251 malicious indicators in Maltiverse are attributed to Bumblebee (S1039). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | hx0hysyg.life | 2026-09-03 | 1 |
| hostname | 6vfmbabg9pc9.live | 2026-09-03 | 1 |
| hostname | hkk3112645hz.live | 2026-09-03 | 1 |
| hostname | wc87pfwqvbx.life | 2026-09-03 | 1 |
| hostname | 2g6py8d93tm.life | 2026-09-03 | 1 |
| hostname | secops.vunetsystems.com | 2026-09-03 | 1 |
| hostname | knof8y1kufn.life | 2026-09-03 | 1 |
| hostname | 3wea9rl1rgeg.live | 2026-09-03 | 1 |
| hostname | rjql4nicl6bg.live | 2026-09-03 | 1 |
| hostname | server.instahosting.in | 2026-09-03 | 1 |
| hostname | 42grunsnoe9w.live | 2026-09-03 | 1 |
| hostname | 0tia8g2yvvo.life | 2026-09-03 | 1 |
| hostname | ilp3urzo9kag.live | 2026-09-03 | 1 |
| hostname | 216-48-179-60.cprapid.com | 2026-09-03 | 1 |
| hostname | e2e-73-176.ssdcloudindia.net | 2026-09-03 | 1 |
| hostname | e2e-73-172.ssdcloudindia.net | 2026-09-03 | 1 |
| hostname | yan95akxgqt.life | 2026-09-03 | 1 |
| hostname | 4kqz7kqt2.life | 2026-09-03 | 1 |
| hostname | 40vzdof7rw3k.live | 2026-09-03 | 1 |
| hostname | 6ijcq51cepr6.live | 2026-09-03 | 1 |
Detection coverage
- 7 YARA rules
- 818 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Checks (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Archive Collected Data (attack-pattern)
- Time Based Checks (attack-pattern)
- Odbcconf (attack-pattern)
- Data from Local System (attack-pattern)
- Security Software Discovery (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Visual Basic (attack-pattern)
- Web Service (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Fallback Channels (attack-pattern)
- Spearphishing Link (attack-pattern)
- Standard Encoding (attack-pattern)
- Rundll32 (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Process Injection (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- EXOTIC LILY (threat-actor)
- TA578 (threat-actor)
- Bumblebee Distribution Campaigns 2023-24 (campaign)
Exploited vulnerabilities
- CVE-2021-40444 (vulnerability)
Detection rules
- MALPEDIA_Win_Bumblebee_Auto (yara-rule)
- CHECK_POINT_Malware_Bumblebee_Packed (yara-rule)
- SEKOIA_Bumblebee_Loader (yara-rule)
- SEKOIA_Loader_Win_Bumblebee (yara-rule)
- CAPE_Bumblebee (yara-rule)
- CAPE_Bumblebeeshellcode_1 (yara-rule)
- CAPE_Bumblebee2024 (yara-rule)
Reports & references
- blog.google — Exposing Initial Access Broker Ties Conti (report)
- proofpoint.com — Bumblebee Is Still Transforming (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
- research.nccgroup.com — Adventures In The Land Of Bumblebee A New Malicious Loader (report)
- Palo Alto Unit 42 — Bumblebee Malware Projector Libra (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- deepinstinct.com — Pindos New Javascript Dropper Delivering Bumblebee And Icedid (report)
- thedfirreport.com — From Bing Search To Ransomware Bumblebee And Adaptixc2 Deliver Akira 2 (report)
- thedfirreport.com — From Bing Search To Ransomware Bumblebee And Adaptixc2 Deliver Akira (report)
- securityintelligence.com — Trickbot Group Systematically Attacking Ukraine (report)
- resecurity.com — Shortcut Based Lnk Attacks Delivering Malicious Code On The Rise (report)
- youtube.com — Watch (report)
- team-cymru.com — Bablosoft Lowering The Barrier Of Entry For Malicious Actors (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bumblebee (report)
- blog.cyble.com — Bumblebee Returns With New Infection Technique (report)
- blog.gigamon.com — Rendering Threats A Network Perspective (report)
- lumu.io — Bumblebee Malware Loader Spotlight (report)
- blog.cyble.com — Bumblebee Loader On The Rise (report)
- youtube.com — Watch (report)
- bin.re — The Dga Of Bumblebee (report)
External references
- mitre-attack — S1039
- Symantec Bumblebee June 2022
- Proofpoint Bumblebee April 2022
- Google EXOTIC LILY March 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy