Experts warn of a new wave of attacks involving the Bumblebee malware, months after Europol’s ‘Operation Endgame‘ that disrupted its operations in May.
Bumblebee was developed by the TrickBot group and replaced the BazarLoader backdoor in ransomware attacks.
The malware is distributed through phishing messages and initiates post-exploitation activities, including reconnaissance and credential theft.
Netskope researchers detected new Bumblebee attacks, which utilize the MSI SelfReg table to execute malicious DLLs directly, making it stealthier.