Saturday, March 8, 2025
HomeCyber Security NewsBumblebee Malware Abuses WebDAV Protocol to Attack Organizations

Bumblebee Malware Abuses WebDAV Protocol to Attack Organizations

Published on

SIEM as a Service

Follow Us on Google News

In recent cybersecurity news, the notorious Bumblebee loader has made a resurgence in a new campaign, posing a significant threat to organizations’ digital security. 

This loader, often used as a stepping stone for ransomware attacks, had taken a pause but reemerged with upgraded techniques.

Intel 471 Malware Intelligence reported that Bumblebee’s operators have returned with updated tactics. 

The malware now employs a Domain Generation Algorithm (DGA) instead of relying on hard-coded command and control servers, making it more resilient.

On September 7, 2023, a fresh campaign utilizing Web Distributed Authoring and Versioning (WebDAV) servers was observed. 

Threat actors used malicious spam emails containing Windows shortcut (.LNK) and compressed archive (.ZIP) files as delivery methods for Bumblebee. Once activated, these files executed commands that downloaded the malware from WebDAV servers.

Bumblebee gained prominence as a loader in September 2021, becoming the preferred choice for threat actors who had previously used BazarLoader. 

Notorious Bumblebee Campaign

It has since been linked to various ransomware payloads, including Cobalt Strike, Metasploit, and Sliver.

This loader’s association with threat actors connected to Conti and Trickbot operations highlights its potency. 

One threat actor aimed to use Bumblebee in a malicious advertising campaign to compromise U.S.-based corporate users, emphasizing its value to cybercriminals.

In this recent campaign, threat actors have leveraged 4shared WebDAV services to distribute the malware. 

The 4shared file-hosting service provides a platform for users to upload and download files via both a web interface and the WebDAV protocol. 

WebDAV enables users to manage and edit files on remote servers, making it a convenient tool.

While the use of WebDAV in malware distribution isn’t new, it played a role in distributing the IcedID (aka Bokbot) malware earlier in the year, as noted by the SANS Internet Storm Center. 

In the Bumblebee campaign, malicious actors sent out spam emails disguised as various documents such as scans, notifications, and invoices. 

These emails contained enticing attachments with filenames like “scan-document_2023(383).lnk” and “invoice-07september_2023(231).lnk.”

Most of the observed samples were distributed as .LNK files. When executed, these .LNK files initiated the Windows command processor, which carried out predefined commands. 

The first command involved mounting a network drive to a WebDAV folder located at “https://webdav.4shared[dot]com” using specific authentication credentials.

Detailed analysis revealed variations in command sets among different samples. After mounting the network drive, subsequent commands differed depending on the specific sample. 

For instance, some used “expand” for file extraction, while others employed “replace.exe” as an alternative method. The approaches to executing these files also varied, utilizing processes like “wmic.exe,” “conhost.exe,” and “schtasks.”

On September 1, 2023, a new version of the Bumblebee loader was detected, featuring significant changes to its architecture. 

It shifted from using the WebSocket protocol to a custom Transmission Control Protocol (TCP) for communication. 

A Domain Generation Algorithm (DGA) was also introduced, replacing the previous hard-coded list of command and control servers. The DGA generated 100 new domains with a “.life” top-level domain (TLD), adding complexity and reducing reliance on static C2 servers.

In the observed WebDAV campaign, four domains were listed, and the fourth domain was successfully resolved and contacted:

  • 3v1n35i5kwx[dot]life
  • cmid1s1zeiu[dot]life
  • Itszko2ot5u[dot]life
  • newdnq1xnl9[dot]life

This evolving Bumblebee loader highlights a coordinated effort by threat actors to enhance evasion tactics and resilience against network scrutiny. The use of 4shared’s WebDAV services as a distribution method represents a novel attack vector. 

Detailed analysis of the .LNK files used in this campaign shows calculated steps to evade detection, including mounting network drives and employing varied command sequences and execution methods.

Intel 471 recommends blocking known malicious domains associated with this campaign and closely monitoring command line event logs for suspicious activity.

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...