Threat Research

    Bumblebee malware has been used for initial access since 2021, with SEO poisoning reported as a delivery method in 2023. In 2025, campaigns impersonating IT tools delivered trojanized software, leading to Bumblebee infections and Akira ransomware deployment. Threat actors leveraged this access to move laterally, steal credentials, install persistent tools, and exfiltrate data....
    Our team observed the reappearance of Bumblebee malware in the cybercriminal landscape on February 8, 2024, following a four-month absence. Bumblebee is a sophisticated downloader favored by various cybercriminal actors since its initial emergence in March 2022, remaining active until October 2023....
    Looking for Something?
    Threat Research Categories:
    Tags