Attackers used BumbleBee malware in a May 2022 intrusion that escalated from a malicious ISO to domain administrator access. The DFIR Report linked initial delivery to a suspected contact-form campaign impersonating legal teams and alleging copyright infringement. The ISO contained a shortcut and DLL that initiated infection, after which attackers deployed Meterpreter and Cobalt Strike, bypassed User Account Control, dumped credentials, and moved laterally through SMB and remote services. Approximately 19 hours after initial access, they exploited Zerologon (CVE-2020-1472) against the primary domain controller and subsequently used pass-the-hash to operate as a member of Domain Admins.
Responders evicted the attackers before further impact was observed, and no ransomware deployment was reported. However, Zerologon exploitation left the primary domain controller unable to authenticate users, disrupting authentication across the environment. The DFIR Report assessed the activity as a likely precursor to ransomware with medium confidence. The incident underscores the importance of remediating Zerologon, restricting privileged lateral movement, and detecting credential dumping. Monitoring should cover both malicious tooling and legitimate process-dumping utilities such as Microsoft Sysinternals ProcDump, whose documentation is included among the supporting references.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Delivery fingerprints associated with the May intrusion suggested that the related BumbleBee campaign continued into June 2022.
Incident responders evicted the attackers before further impact was observed, with no ransomware deployment reported. Zerologon exploitation left the primary domain controller unable to authenticate users, causing authentication failures across the environment.
The attackers copied the Cobalt Strike payload n23.dll to another domain controller and launched it through a service using rundll32.exe.
The attackers executed PowerSploit's Invoke-ShareFinder from the beachhead host to discover domain shares. PowerShell events 4103 and 4104 recorded execution, and sh.txt was apparently intended to hold the output.
After exploiting Zerologon, the attackers used Pass the Hash to operate in the context of an account belonging to the Domain Admins group.
Approximately 19 hours after initial access, following a roughly three-hour pause, the attackers successfully exploited CVE-2020-1472. Network captures and domain-controller event 4742 corroborated the resulting machine-account password change.
The attackers copied Cobalt Strike DLLs to workstation administrative shares under C$\ProgramData and executed them through remote services. The activity apparently established redundant connections.
The attackers used Sysinternals ProcDump64 to dump LSASS memory to C:\ProgramData\lsass.dmp. They also used reg.exe to save the SAM, SECURITY, and SYSTEM registry hives.
Following the UAC bypass, the attackers used Meterpreter's getsystem command to obtain SYSTEM privileges and execute a Cobalt Strike Beacon DLL. They then enumerated domain users, computers, groups, and system information.
After several unsuccessful WSReset bypass attempts and an unsuccessful slui.exe hijacking attempt, the attackers successfully bypassed User Account Control through WSReset and DelegateExecute.
Approximately 37 minutes after ImagingDevices.exe launched, the Meterpreter agent migrated into svchost.exe.
BumbleBee launched ImagingDevices.exe through WmiPrvSE.exe and injected a Meterpreter agent into the process. The agent conducted reconnaissance using nltest, net, tasklist, and whoami.
In May 2022, a suspected contact-form campaign impersonating legal teams directed a victim to a ZIP archive containing StolenImages_Evidence.iso. Opening its documents.lnk shortcut executed the malicious BumbleBee DLL mkl2n.dll.
The DFIR Report documented the intrusion and provided network signatures, Sigma detections, and five YARA rules covering its tools and techniques. It assessed with medium confidence that the activity represented preparation for ransomware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.