🚩
#Bumblebee is still spreading through SEO poisoning, signed malware and fake IT tools targeting mainly network/system administrators.
In addition, Microsoft's ecosystem fails at 3 different layers: search, AI and protection ⚠️
1.- Bing, shows as first result a fake NetCrunch site.
2.- Copilot, suggests downloading from the same malicious site.
3.- Defender, doesn't detect the downloaded malware.
Fake domain: netcrunch[.]org mentioned here
x.com/1ZRR4H/status/19251137… (and as
@tsnikle commented, if accessed directly, the site shows a harmless version).
Download from: hub28[.]shop
Sample (43,7 MB):
tria.ge/250522-whxansbp3w
Botnet: grp0004
C2 server: 188.40.187.139 (DGA)
As a general recommendation, block all traffic for .life and .click domains in the corporate network.
@malwrhunterteam
🚩 Other active domains and potentially linked to this campaign or threat actors:
- netcrunch[.]org
- nir-soft[.]org
- rvtools[.]org
- zenmap[.]pro
- sonicwall[.]pro
- hanwhavision[.]org
- pulsesecure[.]pro
- vmwarehorizon[.]org
- checkpointvpn[.]org
- windirstat[.]pro
- softped[.]shop
- softinger[.]org
💡 Pulse Secure VPN, SonicWall NetExtender and Wisenet Device Manager sites use an almost identical template.