HomeSecurityBumblebee malware adds post-exploitation tool for stealth infections

Bumblebee malware adds post-exploitation tool for stealth infections

A new version of the Bumblebee malware loader has been detected being used by hackers, with a new infection chain that uses the PowerSploit framework to covertly reflectively inject a DLL payload into memory.

See also: How to install Session Messenger on Windows?

Bumblebee malware adds post-exploitation tool for stealth infections

Bumblebee was discovered in April, participating in phishing believed to be orchestrated by the same hackers behind BazarLoader and TrickBot, namely the Conti syndicate.

As Bumblebee is a sophisticated loader program with advanced anti-analysis and anti-detection features, it is supposed to replace other loaders, such as BazarLoader, in initial compromise attacks followed by ransomware deployment.

Bumblebee's distribution rate reached remarkable levels in the following months, however the new loader never became dominant in the field.

According to a report by Cyble, based on a finding by threat researcher Max Malyutin, the authors of Bumblebee are preparing a return from the summer break of spam, using a new execution flow.

See also: Lazarus Group targets US energy providers

Execution from memory

Previously, Bumblebee communicated with victims via emails that contained password- compressed ISO files containing an LNK (to execute the payload) and a DLL file (the payload).

In the recent attack, Bumblebee replaced the ISO with a VHD (Virtual Hard Disk) file, which, again, contains a LNK shortcut file (Quote).

Bumblebee

Instead of directly executing Bumblebee (DLL), the LNK now executes “imagedata.ps1”, which launches a PowerShell window and hides it from the user by abusing the “ShowWindow” command.

See also: 8 out of 10 sites leak their visitors' "search terms"

The SP1 script is obfuscated using Base64 and string concatenation to avoid AV detection when loading the second stage of the PowerShell.

Bumblebee malware adds post-exploitation tool for stealth infections

The second stage features the same obfuscation as the first and contains the PowerSploit module to load the 64-bit malware (LdrAddx64.dll) into the PowerShell process's memory using reflective injection.

Bumblebee

With the new loading flow, Bumblebee loads from memory and never touches the host disk, thus minimizing the chances of detection and interruption by anti-virus tools.

By increasing its stealth, Bumblebee becomes a more potent early access threat and increases its chances of luring ransomware and malware operators looking for ways to deploy their payloads .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS