Researchers reported that the Bumblebee malware loader continues to evolve its initial access methods, moving beyond earlier PowerShell-heavy chains to newer delivery mechanisms including a JavaScript dropper and trojanized software installers. Deep Instinct said a new JavaScript-based dropper identified by its distinctive PindOS user-agent downloads DLL payloads from hardcoded URLs, stores them under %appdata%/Microsoft/Templates/, and launches them with rundll32.exe, while also supporting a PowerShell fallback path. The same dropper has been used to deliver both Bumblebee and IcedID, underscoring its role as a flexible malware distribution tool tied to ransomware-enabling intrusion activity.
Other reporting shows Bumblebee has repeatedly changed infection chains while preserving its role as a loader for follow-on payloads such as Cobalt Strike, Sliver, Meterpreter, and ransomware. Earlier campaigns analyzed by Cyble used spam emails with password-protected attachments containing VHD files and malicious LNK shortcuts that triggered obfuscated PowerShell, Base64 decoding, gzip decompression, and reflective DLL injection via PowerSploit. VMRay found that once executed, Bumblebee uses packed or obfuscated binaries, extensive anti-analysis checks, and command-and-control over HTTP and later WebSockets to support shellcode injection, DLL injection, download-and-execute, persistence, shell execution, and plugin loading, highlighting a mature loader that is adapting both delivery and post-compromise tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
VMRay reported that BumbleBee temporarily removed its evasion logic and later restored it around November 2022, marking a notable change in the malware's anti-analysis behavior.
VMRay reported that BumbleBee added the "plg" command around August 2022, further extending its command set for loading plugins from command-and-control infrastructure.
Cyble said the September 2022 payload behavior was similar to a Bumblebee variant the same researchers had analyzed in June 2022, indicating continuity in the malware's core functionality.
VMRay reported that BumbleBee added the "gdt" command around April 2022, expanding its command-and-control capabilities to execute shell commands on infected systems.
Deep Instinct stated that Bumblebee was first discovered in March 2022. The malware loader later became associated with Conti and used as a replacement for BazarLoader.
Deep Instinct noted that IcedID has been observed in the wild since at least 2017, establishing the malware family later delivered by the PindOS dropper.
VMRay analyzed BumbleBee's post-infection behavior, describing unpacking, command-and-control communications, and more than 50 evasion techniques. The report said older samples used HTTP while more recent versions adopted WebSockets and supported commands for injection, persistence, download-and-execute, uninstall, shell execution, and plugin loading.
Deep Instinct reported infection infrastructure used by the PindOS dropper, including multiple URLs for Bumblebee and IcedID payload delivery. The payloads were generated pseudo-randomly on demand to vary hashes and reduce signature-based detection.
Deep Instinct's Threat Research Lab identified a new JavaScript-based dropper distinguished by the "PindOS" user-agent string and Russian-language comments. The dropper was observed delivering both Bumblebee and IcedID via hardcoded URLs and rundll32-based execution.
Cyble Research & Intelligence Labs analyzed a Bumblebee campaign delivered through spam emails with password-protected VHD attachments containing a malicious LNK and PowerShell scripts. The chain used obfuscation, Base64 decoding, gzip decompression, and reflective PE injection to load the final Bumblebee DLL into powershell.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcevmray.com
Open sourcedeepinstinct.com
Open sourceblog.cyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.