Researchers reported a new Bumblebee malware campaign that suggests the loader has resumed activity after Europol’s Operation Endgame disrupted Bumblebee and other major droppers. In the newly observed chain, victims are lured by phishing emails into opening a ZIP archive containing an LNK file that launches PowerShell, downloads an MSI installer, and executes it with msiexec. Instead of dropping a DLL to disk or spawning conspicuous child processes, the MSI abuses the Windows Installer SelfReg mechanism to load a DLL from an embedded CAB file and invoke DllRegisterServer directly in memory, a stealthier variation on Bumblebee delivery.
The payload retained hallmark Bumblebee traits, including RC4-encrypted configuration data decrypted with the hardcoded key NEW_BLACK, port 443, and campaign IDs msi and lnk001. Bumblebee emerged in 2022 as a widely used initial-access loader tied to actors such as TA578 and TA579, commonly delivered through thread hijacking, contact-form abuse, ZIP or ISO archives, LNK files, and malicious DLL execution. Prior reporting linked the malware to follow-on deployment of Cobalt Strike, Sliver, Meterpreter, IcedID, and ransomware-associated operations connected to groups including Conti, Diavol, LockBit, and AvosLocker, underscoring that its return could restore a proven access path into enterprise networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
In May 2024, Europol's Operation Endgame targeted major dropper botnets including Bumblebee, IcedID, and Pikabot, with over 100 servers taken down and four arrests reported.
CloudSEK published technical analysis showing Bumblebee unpacking its payload in memory, hooking ntdll APIs, hollowing gdiplus.dll, and using anti-VM checks, persistence, and APC-based injection.
Cyble published analysis stating that Bumblebee infections were on the rise and describing phishing-driven ISO and LNK-based delivery chains used to deploy the loader and follow-on payloads.
Sekoia reported that the number of identified active Bumblebee command-and-control servers grew from about five in early April 2022 to more than 130 by early June 2022, indicating rapid adoption.
SANS published analysis of the 2022-05-18 EXOTIC LILY-related infection, showing Bumblebee C2 traffic followed by HTTPS traffic to Amazon EC2 and then Cobalt Strike communications to xenilik.com.
On 2022-05-18, an analyzed infection chain used malicious TransferXL links to deliver a ZIP containing an ISO with New Folder.lnk and spc.dll, which executed Bumblebee via rundll32.exe.
On 2022-05-09, TA578 used thread-hijacked emails with either storage.googleapis.com links or password-protected ZIP attachments to deliver ISO files containing documents.lnk and ramest.dll for Bumblebee execution.
The domain wolsleyindustrialgroup.com, later associated with malicious TransferXL links used in a Bumblebee infection chain, was registered on 2022-04-29.
The domain southerncompanygas.co, later tied to Bumblebee-related TransferXL activity, was registered on 2022-04-27.
In April 2022, Proofpoint observed a thread-hijacking campaign using password-protected ZIP files named in the doc_invoice pattern; the attached ISO contained DOCUMENT.LNK and tar.dll to launch Bumblebee.
Proofpoint published research describing Bumblebee as a new loader being distributed by multiple crimeware actors, and assessed that several actors previously tied to BazaLoader had transitioned to Bumblebee.
Sekoia reported that it began tracking Bumblebee in early April 2022 and initially identified about five active command-and-control servers.
In March 2022, Proofpoint observed a TA578 contact-form abuse campaign claiming stolen images were on the target website and delivering an ISO with DOCUMENT_STOLENIMAGES.LNK and neqw.dll to execute Bumblebee.
In March 2022, Proofpoint observed a TA579 campaign using DocuSign-themed lures that led victims to a zipped ISO or HTML redirect chain, with the ISO containing ATTACHME.LNK and Attachments.dat to launch Bumblebee.
Multiple sources state that Bumblebee was first discovered and reported in March 2022 as a new malware loader/downloader used for initial access and follow-on payload delivery.
Proofpoint reported that BazaLoader had not appeared in its telemetry since February 2022, a shift that supported later assessments that some actors moved to Bumblebee.
Reporting on later campaigns states that TA578 had been observed distributing both Bumblebee and IcedID since February 2022, marking the start of its use of Bumblebee in documented activity.
Netskope Threat Labs reported a new phishing-to-ZIP-to-LNK-to-MSI infection chain delivering Bumblebee, the first Bumblebee campaign it had seen since Operation Endgame, suggesting the malware's resurgence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcenetskope.com
Open sourcecloudsek.com
Open sourceblog.cyble.com
Open sourceproofpoint.com
Open sourcelearn.microsoft.com
Open sourceblog.google
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.