Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1039
MITRE ATT&CK Malware

Bumblebee (S1039)

ShareXLinkedInRedditHN

[Bumblebee](https://attack.mitre.org/software/S1039) is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. [Bumblebee](https://attack.mitre.org/software/S1039) has been linked to ransomware operations including [Conti](https://attack.mitre.org/software/S0575), Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.(Citation: Google EXOTIC LILY March 2022)(Citation: Proofpoint Bumblebee April 2022)(Citation: Symantec Bumblebee June 2022)

Platforms: Windows

▪Techniques implemented (39)

T1082System Information DiscoveryT1033System Owner/User DiscoveryT1047Windows Management InstrumentationT1041Exfiltration Over C2 ChannelT1059.003Windows Command ShellT1497.001System ChecksT1140Deobfuscate/Decode Files or InformationT1055.001Dynamic-link Library InjectionT1560Archive Collected DataT1497.003Time Based ChecksT1218.008OdbcconfT1005Data from Local SystemT1518.001Security Software DiscoveryT1055.004Asynchronous Procedure CallT1059.005Visual BasicT1102Web ServiceT1497Virtualization/Sandbox EvasionT1105Ingress Tool TransferT1008Fallback ChannelsT1566.002Spearphishing LinkT1132.001Standard EncodingT1218.011Rundll32T1036.005Match Legitimate Resource Name or LocationT1055Process InjectionT1106Native APIT1027Obfuscated Files or InformationT1129Shared ModulesT1012Query RegistryT1573.001Symmetric CryptographyT1548.002Bypass User Account ControlT1057Process DiscoveryT1204.001Malicious LinkT1566.001Spearphishing AttachmentT1053.005Scheduled TaskT1204.002Malicious FileT1059.001PowerShellT1559.001Component Object ModelT1622Debugger EvasionT1070.004File Deletion

▪Used by groups (2)

G1038TA578G1011EXOTIC LILY
S1039on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.