Bumblebee is a Windows malware loader first observed in early 2022 that provides initial access and deploys additional malware and post-exploitation tools. It has been used by Exotic Lily, also known as TA580 and PROJECTOR LIBRA, and TA578. Observed payloads include Meterpreter agents and Cobalt Strike Beacons. Its role is principally payload delivery and execution rather than ransomware encryption or credential theft, although Bumblebee infections can enable subsequent credential dumping, lateral movement, and ransomware-related intrusions.
Distribution commonly involves phishing links or attachments, including hijacked email threads, fake copyright complaints submitted through website contact forms, and business-opportunity impersonation. Attackers use legitimate file-sharing services and deceptive document-download pages to deliver archives or disk images containing Windows shortcuts and malicious DLLs or PowerShell loaders. Executing a shortcut initiates the infection, sometimes loading the Bumblebee DLL directly and sometimes using staged scripts to load it in memory. Bumblebee has also been delivered through OneNote documents and campaigns exploiting the WinRAR vulnerability CVE-2023-38831, and has been deployed as a post-compromise payload by Raspberry Robin.
Bumblebee communicates with command-and-control infrastructure to receive instructions for downloading and executing payloads, injecting shellcode or DLLs, executing shell commands, loading plugins, establishing persistence, and uninstalling itself. Persistence mechanisms include Visual Basic scripts and scheduled tasks. It supports UAC bypass to deploy tools with elevated privileges and performs user, system, process, security-software, and registry discovery. Associated behaviors also include data archiving and exfiltration over its command-and-control channel. Older versions used HTTP communications, while later versions adopted WebSockets; configurations may be stored in plaintext or encrypted with RC4.
Bumblebee is frequently packed or obfuscated and has been extensively associated with the Forest crypter. Its anti-analysis logic detects debuggers, analysis tools, virtualization artifacts, sandbox-associated names, unusual hardware characteristics, and lack of mouse activity. Much of this logic derives from the open-source Al-Khaser project. Bumblebee infrastructure was targeted during Operation Endgame in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
Tracking Bumblebee’s Development ... CrowdStrike Name: Shindig ... First reporting of Bumblebee ... Bumblebee Overview ... Loader / Main DLL Development ... C2 Communication Development
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Exotic Lily has been known to use Windows shortcuts to deploy the loader “BumbleBee”.
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Cynet’s Threat Research and Intelligence team recently discovered a new malware campaign called BumbleBee. From our initial analysis, BumbleBee is a custom new loader that is used by different IAB groups.
Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
A newly discovered malware loader called Bumblebee is likely the latest development of the Conti syndicate, designed to replace the BazarLoader backdoor used to deliver ransomware payloads.
Intel 471 researchers have noticed that the Conti group appears to have dropped BazarLoader in favor of a new malware called Bumblebee... Google stating that Bumblebee has been used by an access broker with ties to Conti.
42 distinct techniques documented for this family, organized by ATT&CK tactic.
%windir%\system32\cmd.exe /c start rundll32.exe mkl2n.dll,kXlNkCKgFC
When a victim double-clicks on the PDF, the vulnerability will quietly launch a script in the folder to install malware on the device.
690 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial-access loader delivering secondary payloads through phishing and compromised websites. The article links its role to ransomware access and describes disruptions in 2024 and 2025.
A sophisticated loader used by initial access brokers to gain an initial foothold, evade analysis and detection, contact C2 infrastructure, and download and execute second-stage payloads that can lead to ransomware deployment.
Threat actors abusing WebDAV is a common tactic, seen in past attacks delivering Bumblebee and Voldemort malware.
Bumblebee2
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.