Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
"The next optional method supports running arbitrary PowerShell command supplied by the threat actor"
Bumblebee’s injection module ( dij command for DLL Injection) dynamically resolves NtQueueApcThread at runtime and uses it to inject a payload DLL... While the static import of NtQueueApcThread is flagged by multiple scanners, a runtime GetProcAddress lookup on ntdll.dll is invisible to import-table analysis.
Process injection sits at the top of the MITRE ATT&CK heap for the second year running. Picus Labs’ Red Report 2025 found T1055 in roughly 31% of the million-plus malware samples they examined.
Attackers spawn a process suspended, queue an APC into its main thread before the AV/EDR’s user-mode hooks have loaded, then resume. The payload runs before the security product begins.
"RunPE , also known as Process Hollowing... creating a process in a suspended state... unmapping... overwriting... resuming..."
"Junk data around 260 – 300 MB... cause issues with AV/EDR as they have file size limitations on uploads..."
Process injection sits at the top of the MITRE ATT&CK heap for the second year running. Picus Labs’ Red Report 2025 found T1055 in roughly 31% of the million-plus malware samples they examined.
Attackers spawn a process suspended, queue an APC into its main thread before the AV/EDR’s user-mode hooks have loaded, then resume. The payload runs before the security product begins.
"RunPE , also known as Process Hollowing... creating a process in a suspended state... unmapping... overwriting... resuming..."
"...opening a file handle with FILE_SHARE_READ permissions only and having explorer.exe receive the handle via... DuplicateHandle()."
"Parent process spoofing... OpenProcess... InitializeProcThreadAttributeList... UpdateProcThreadAttribute..."
The Pure Crypter reads the separate data included within and then decrypts it to obtain configuration values for performing malicious actions set as desired. After extracting the configuration values, an additional malware payload is read from the resource and decrypted.
"...executes several checks against virtual machines... WMI queries... searching for strings... 'VMware|VIRTUAL|...|Xen'... checks against loaded modules... 'SbieDll.dll'... 'cuckoomon.dll'..."
"The optional Execution Delay feature makes use of the Windows API SleepEx..."
"...executes several checks against virtual machines... WMI queries... searching for strings... 'VMware|VIRTUAL|...|Xen'... checks against loaded modules... 'SbieDll.dll'... 'cuckoomon.dll'..."
"There are two options in Pure Crypter to disable AMSI... patching the AmsiScanBuffer API in memory..." | "...disables the internet via the LOLBin ipconfig.exe... prevent AV/EDR from communicating with their backend..." | "...use of PowerShell to add an exclusion to Windows Defender..." | "...found an elementary bypass by simply patching the NtManageHotPatch API in memory..." | "...load 'clean' copies of kernel32.dll... and ntdll.dll, effectively bypassing any hooks already put in place by AV/EDR."
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypter that patches NtManageHotPatch in memory to bypass Windows hotpatching mitigations and restore RunPE/Early Bird APC reliability.
MaaS loader/crypter used to pack and execute secondary payloads on Windows. Provides multiple evasion and persistence features (e.g., AMSI/ETW patching, DLL unhooking, anti-VM/anti-debug, Defender exclusions, persistence via Run key/scheduled task/startup VBS) and supports several payload execution methods (reflection for .NET, RunPE/process hollowing with a Windows 11 24H2 bypass via NtManageHotPatch patching, and shellcode execution).
A C# malware loader/crypter sold as SaaS on underground forums that decrypts configuration and payload data, uses process injection/process hollowing, and loads Lumma Stealer into another process for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.