Proofpoint researchers reported that the Bumblebee malware has resurfaced after a few months of absence from the threat landscape.

The most recent campaign was detected in February 2024 and the method of attack was different from previous ones.
The Bumblebee malware was used by multiple cybercriminals from March 2022 to October 2023. In total, Proofpoint detected 230 Bumblebee campaigns during these months.
The malware is primarily used for initial access, to download and execute additional payloads, such as Cobalt Strike, shellcode, Sliver, and Meterpreter.
See also: Hunter-Killer malware method continues to grow
Criminals have used various methods to distribute Bumblebee. For example, in April 2023, malicious versions of popular software tools such as Zoom, Cisco AnyConnect, ChatGPT , and Citrix Workspace to infect victims.
Bumblebee malware: New campaign
Proofpoint said that Bumblebee “disappeared” in October 2023. Its new distribution campaign was detected in February 2024.
The attackers used social engineering techniques to trick targets into downloading the Bumblebee malware. In the campaign, several thousand emails were sent from the address info@quarlesaa[.]com to organizations in the US. The emails had the subject line “ Voicemail February ”. The malicious emails contained OneDrive URLs , which led to a Word file with names such as “ ReleaseEvans#96.docm ”.
This Word document used the brand name of the electronics company Humane.
The documents used macros to create a script in the Windows temporary directory, with the installed file being executed using “wscript“.
Inside the temporary file was a PowerShell, which downloaded and executed the next stage of the attack, from a remote server.
See also: Raspberry Robin malware evolves with one-day exploits
This next stage was another PowerShell command stored in the “update_ver” file that downloaded and ran the Bumblebee DLL.
Researchers noticed that the new Bumblebee campaign had some distinct characteristics compared to previous attacks. For example, the use of VBA macro-enabled documents was observed in the attack chain.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Previous Bumblebee malware campaigns used combinations of URLs and attachments and exploited vulnerabilities.
Proofpoint was unable to attribute the new campaign to a specific threat, but researchers noted that some of the techniques used align with previous activities by the TA579.
Proofpoint noticed that several teams had taken a break towards the end of last year but have now returned.
“2024 began with a boom for cyber threat actors ,with activity returning to very high levels after a temporary winter lull. Proofpoint researchers continue to observe new, creative attack chains, detection evasion attempts, and updated malware from multiple threat actors,” the researchers wrote.
See also: XLoader Android malware: New version runs automatically on device

Protection
The above shows that a number of measures are necessary to protect against Bumblebee malware. First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from such attacks.
Second, it is recommended to use strong, unique passwords. This can help protect accounts from being compromised and exploited by the Bumblebee malware.
Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.
Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove Bumblebee malware is emphasized.
Source: www.infosecurity-magazine.com
