216.73.216.6

New Bumblebee Loader Infection Chain Signals Possible Resurgence

· Published 21/10/2024 10:59 · Modified 21/10/2024 11:24

Export JSON

Essential information

Published
21/10/2024 10:59
Modified
21/10/2024 11:24
Tags
2024-10-21 bumblebee cobalt strike darkgate icedid in-memory execution infection chain latrodectus lnk loader msi phishing pikabot stealth
Related entities
11 observables, 8 techniques (mitre), 6 malware

Description

A new for the malware has been discovered, potentially indicating its resurgence after Operation Endgame. The sophisticated downloader, first identified in March 2022, is used by cybercriminals to access corporate networks and deliver payloads like beacons and ransomware. The infection likely begins with a email containing a ZIP file with an file. When executed, it triggers a series of events to download and execute the payload in memory. The new approach uses files disguised as Nvidia and Midjourney installers, employing a stealthier method to avoid creating new processes and writing the payload to disk. This technique differs from previous campaigns and demonstrates the evolving tactics of the threat actors behind .

External references