Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

BumbleBee: Round Two

released on 2022-09-26 @ 12:48:04 PM
In this intrusion from May 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee has been identified as an initial access vector utilized by several ransomware affiliates. In the intrusion, we see the threat actor use BumbleBee to deploy Cobalt Strike and Meterpreter. The threat actor then used RDP and SMB to move around the network looking at backup systems and file shares before being evicted from the network.