Threat Advisory

Bumblebee Malware Distributed Via Trojanized Installer Downloads

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Through Google Ads and SEO poisoning, the business-targeting Bumblebee malware is spread, pushing well-known software like Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace. Bumblebee is a malware loader that was found in April 2022 and is believed to have been created by the Conti team to replace the BazarLoader backdoor, which was used to gain initial access to networks and launch ransomware attacks. Researchers recently discovered a new operation that targets unwary users with trojanized versions of popular programmes promoted through Google AdWords. One of the campaigns that the researchers observed began with a Google ad that advertised a fake download page for the Cisco AnyConnect Secure Mobility Client that has been created and hosted on a domain.[/subscribe_to_unlock_form]

Summary:

Through Google Ads and SEO poisoning, the business-targeting Bumblebee malware is spread, pushing well-known software like Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace. Bumblebee is a malware loader that was found in April 2022 and is believed to have been created by the Conti team to replace the BazarLoader backdoor, which was used to gain initial access to networks and launch ransomware attacks. Researchers recently discovered a new operation that targets unwary users with trojanized versions of popular programmes promoted through Google AdWords. One of the campaigns that the researchers observed began with a Google ad that advertised a fake download page for the Cisco AnyConnect Secure Mobility Client that has been created and hosted on a domain.[emaillocker id="1283"]

The user was directed to this fake download page through an infection chain that started with a malicious Google Ad and went through a compromised WordPress website. The "cisco-anyconnect-4_9_0195.msi" trojanized MSI installer, which installs the BumbleBee malware, was distributed on this fake landing page. Upon execution, the user's computer receives a copy of the legitimate program installer and a PowerShell script with the fake name (cisco2.ps1). The PowerShell script compromises the device and installs the BumbleBee malware Additionally, it has a Bumblebee malware payload that is encoded and loaded into memory reflectively. This indicates that Bumblebee continues to load the malware into memory using the same post-exploitation framework module, undetected by current antivirus software.

Devices that have been infected are prime targets for the start of a ransomware attack because the trojanized software targets corporate users. One of the most recent Bumblebee attacks was carefully studied by researchers. They discovered that three hours after the initial infection, the threat actor used their access to the compromised system to move laterally across the network. The Cobalt Strike pen-test suite, AnyDesk, and DameWare remote access tools, network scanning utilities, an AD database dumper, and a Kerberos credentials stealer are among the tools the attackers used on the compromised environment. This arsenal of tools produces an attack profile that strongly suggests that the malware operators are interested in discovering network points that are accessible, moving to other computers, stealing data, and ultimately installing ransomware.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/google-ads-push-bumblebee-malware-used-by-ransomware-gangs/

[/emaillocker]
crossmenu