{ "type": "bundle", "id": "bundle--f640dd44-2cda-4ca1-a168-1577de6e2593", "spec_version": "2.0", "objects": [ { "modified": "2022-10-21T21:43:41.253Z", "name": "Bumblebee", "description": "[Bumblebee](https://attack.mitre.org/software/S1039) is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. [Bumblebee](https://attack.mitre.org/software/S1039) has been linked to ransomware operations including [Conti](https://attack.mitre.org/software/S0575), Quantum, and Mountlocker and derived its name from the appearance of \"bumblebee\" in the user-agent.(Citation: Google EXOTIC LILY March 2022)(Citation: Proofpoint Bumblebee April 2022)(Citation: Symantec Bumblebee June 2022)\n", "x_mitre_platforms": [ "Windows" ], "x_mitre_deprecated": false, "x_mitre_domains": [ "enterprise-attack" ], "x_mitre_version": "1.0", "x_mitre_contributors": [ "Phill Taylor, BT Security" ], "x_mitre_aliases": [ "Bumblebee" ], "type": "malware", "id": "malware--04378e79-4387-468a-a8f7-f974b8254e44", "created": "2022-08-19T20:28:36.981Z", "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", "revoked": false, "external_references": [ { "source_name": "mitre-attack", "url": "https://attack.mitre.org/software/S1039", "external_id": "S1039" }, { "source_name": "Symantec Bumblebee June 2022", "description": "Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.", "url": "https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime" }, { "source_name": "Proofpoint Bumblebee April 2022", "description": "Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.", "url": "https://www.proofpoint.com/us/blog/threat-insight/bumblebee-is-still-transforming" }, { "source_name": "Google EXOTIC LILY March 2022", "description": "Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.", "url": "https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/" } ], "object_marking_refs": [ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" ], "labels": [ "malware" ], "x_mitre_attack_spec_version": "2.1.0", "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5" } ] }