Hidden Bee is a Windows cryptocurrency-mining malware family associated with the Underminer exploit kit and active since at least 2018. It is also referred to as Hidden Mellifera. The malware is notable for distributing its components in proprietary executable formats derived from but substantially stripped down from the Portable Executable format, including formats referred to as NE and NS. These custom formats support manual in-memory loading, relocations, hashed import resolution, and custom exception-handling logic, reflecting an emphasis on modularity and analysis resistance.
Hidden Bee was primarily delivered through drive-by exploitation via the Underminer exploit kit, which used browser and Adobe Flash vulnerabilities to compromise victims. Campaign reporting linked activity heavily to parts of Asia, particularly Japan, Taiwan, and South Korea. Underminer infections were described as deploying a bootkit for persistence before delivering the Hidden Bee coin-mining payload.
The family’s final payload was a coin miner implemented with Lua-based components, indicating a modular architecture in which scripting played a central role. Hidden Bee has also been identified as an important predecessor in the development lineage of Rhadamanthys, with strong architectural overlap in custom executable formats, virtual filesystem concepts, steganographic payload delivery, Lua usage, shared-memory mechanisms, and 32-bit to 64-bit loading techniques. Last observed samples referenced in the available reporting date to 2021.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers have spotted only three. They are: CVE-2018-4878 —a use-after-free vulnerability in Adobe Flash Player patched in February 2018
Researchers have spotted only three. They are: CVE-2016-0189 —a memory corruption vulnerability in Internet Explorer (IE) patched in May 2016
Researchers have spotted only three. They are: CVE-2015-5119 —a use-after-free vulnerability in Adobe Flash Player patched in July 2015
The features of the 6 types of Exploit Kits currently observed are as follows ... Spelevo No No CVE-2018-8174, CVE-2018-15982 ... Underminer Yes No CVE-2018-15982
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Just like Hidden Bee, Rhadamanthys can run LUA scripts.
For this purpose, the author decided to use a shared memory area that is accessed by different processes via named mapping.
They are: CVE-2015-5119 —a use-after-free vulnerability in Adobe Flash Player patched in July 2015; CVE-2016-0189 —a memory corruption vulnerability in Internet Explorer (IE) patched in May 2016; CVE-2018-4878 —a use-after-free vulnerability in Adobe Flash Player patched in February 2018
most of the core modules are delivered in the form of custom executable formats
The function denoted as parse_response is responsible for decoding the next stage that was downloaded from the C2 and hidden in a media file (JPG).
Writing a Loader Module for Hidden Bee After reading the aforementioned write-up, I figured that the only difficulties in loading Hidden Bee images in IDA would be A) that the Hidden Bee customized header specifies API imports via hash rather than by name... Imports For dealing with the imports by hash...
the EK has been seen using encrypted TCP tunnels to deploy a bootkit first —for OS persistence— and then a coinminer
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a likely predecessor malware family with similar custom executable formats to Rhadamanthys.
Hidden Bee is mentioned only for comparison because Rhadamanthys custom file formats were related to formats previously used by Hidden Bee.
An older multi-stage malware family first seen around 2018 whose final payload was a coin miner implemented with LUA scripts. The report presents it as the likely predecessor to Rhadamanthys due to overlapping custom formats, virtual filesystems, code reuse, steganography, and loader design.
Unique malware delivered by the Underminer exploit kit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.