Hidden Bee
- First seen
- 2018-04-01 00:00:00
- Malware type
- botnet, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:05:23
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ru
Context
Hidden Bee is a malware family known for its complex infection chains. It has been used to form botnets and mine cryptocurrency, showcasing advanced evasion techniques.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Hiddenbee (report)
- blog.malwarebytes.com — Reversing Malware In A Custom Format Hidden Bee Elements (report)
- blog.malwarebytes.com — Hidden Bee Lets Go Down The Rabbit Hole (report)
- bleepingcomputer.com — New Underminer Exploit Kit Discovered Pushing Bootkits And Coinminers (report)
- freebuf.com — 175106 (report)
- freebuf.com — 174581 (report)
- blog.malwarebytes.com — Hidden Bee Miner Delivered Via Improved Drive By Download Toolkit (report)
- msreverseengineering.com — Weekend Project A Custom Ida Loader Module For The Hidden Bee Malware Family (report)
- blog.malwarebytes.com — The Hidden Bee Infection Chain Part 1 The Stegano Pack (report)
- research.checkpoint.com — From Hidden Bee To Rhadamanthys The Evolution Of Custom Executable Formats (report)