Tag: Bumblebee Malware

Fake Zenmap. WinMRT sites target IT staff with Bumblebee malware
News

Fake Zenmap. WinMRT sites target IT staff with Bumblebee malware

More typosquatting sites are being utilized by the Bumblebee malware SEO poisoning operation, which was discovered earlier this week and impersonates RVTools, to infect IT staff devices by imitating other well-known open-source projects. Using the popularity of Zenmap, the GUI for the Nmap network scanning tool, and the WinMTR tracerout software, BleepingComputer was able to identify two cases. IT professionals frequently utilize these two programs to diagnose or analyze network traffic; however, some of their functions require administrative access. Because of this, threat actors target users of these technologies in an attempt to compromise corporate networks and propagate laterally to additional devices. Zenmap[.]pro and winmtr[.]org are the two domains through which the Bumbl...
RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer
News

RVTools Official Site Hacked to Deliver Bumblebee Malware via Trojanized Installer

An infected installer for the well-known VMware environment reporting tool has been made available on the official RVTools website. RVTools.com and Robware.net are not operational at the moment. In a statement published on its website, the business wrote, "We appreciate your patience and are working quickly to restore service." The only approved and supported websites for RVTools software are Robware.net and RVTools.com. Avoid using any other websites or sources to look for or download alleged RVTools software. The development follows security researcher Aidan Leon's disclosure that a malicious DLL—which turned out to be Bumblebee, a known malware loader—was being sideloaded via an infected version of the installer that was downloaded from the website read more about RVTools Offi...
Bumblebee malware returns after recent law enforcement disruption
News

Bumblebee malware returns after recent law enforcement disruption

More than four months after being blocked by Europol during 'Operation Endgame' in May, the Bumblebee malware loader has been observed in new attacks. The malware, which is thought to have been developed by TrickBot authors, first appeared in 2022 as a substitute for the BazarLoader backdoor, giving ransomware threat actors access to victim networks. Usually, phishing, malvertising, and SEO poisoning are used by Bumblebee to get infected and sell different products (such Zooom, Cisco AnyConnect, ChatGPT, and Citrix Workspace). Information-stealing malware, several ransomware strains, and Cobalt Strike beacons are some of the payloads that Bumblebee usually delivers read more about Bumblebee malware returns after recent law enforcement disruption. Get up to date on the latest c...
Bumblebee Malware Returns with New Tricks Targeting U.S. Businesses
News

Bumblebee Malware Returns with New Tricks Targeting U.S. Businesses

Following a four-month hiatus, the notorious malware loader and initial access broker known as Bumblebee has reappeared as part of a fresh phishing campaign that was noticed in February 2024. The operation, according to enterprise security company Proofpoint, targets American businesses with voicemail-themed baits that link to OneDrive URLs. The business stated in a report on Tuesday that "the URLs linked to a Word file with names such as "ReleaseEvans#96.docm" (the digits before the file extension varied). "The Word document spoofed the consumer electronics company Humane." By utilizing VBA macros, opening the document initiates a PowerShell script that downloads and runs another PowerShell script from a remote server read more Bumblebee Malware Returns with New Tricks Targeting...