Source |
The Hacker News |
Identifiant |
6391142 |
Date de publication |
2022-08-18 02:20:52 (vue: 2022-08-18 11:05:30) |
Titre |
Hackers Using Bumblebee Loader to Compromise Active Directory Services |
Texte |
The malware loader known as Bumblebee is being increasingly co-opted by threat actors associated with BazarLoader, TrickBot, and IcedID in their campaigns to breach target networks for post-exploitation activities.
"Bumblebee operators conduct intensive reconnaissance activities and redirect the output of executed commands to files for exfiltration," Cybereason researchers Meroujan Antonyan and |
Notes |
|
Envoyé |
Oui |
Condensat |
active activities actors antonyan associated bazarloader being breach bumblebee campaigns commands compromise conduct cybereason directory executed exfiltration exploitation files hackers icedid increasingly intensive known loader malware meroujan networks operators opted output post reconnaissance redirect researchers services target threat trickbot using |
Tags |
Malware
Threat
|
Stories |
|
Move |
|
Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2022-08-19 14:35:51 |
(Déjà vu) Hackers Using Bumblebee Loader To Compromise Active Directory Services (lien direct) |
The malware loader known as Bumblebee is being increasingly co-opted by threat actors associated with BazarLoader, TrickBot, and IcedID in their campaigns to breach target networks for post-exploitation activities. “Bumblebee operators conduct intensive reconnaissance activities and redirect the output of executed commands to files for exfiltration,” Cybereason researchers Meroujan Antonyan and Alon Laufer said in a technical write-up. |
Malware
Threat
|
|
|