Skip to main content
Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader operation cover
COMING SOONIntermediate

Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader

An ISO image attachment hides a visible shortcut beside a hidden DLL. The user mounts the container and runs the shortcut, which executes the Bumblebee loader via rundll32 against a DLL export. Bumblebee injects into a signed Windows Mail binary through WMI, beacons HTTPS to a C2 cluster, then layers a Meterpreter stager and a Cobalt Strike beacon. The operator runs AdFind discovery, dumps LSASS with ProcDump, creates a rogue local admin, installs AnyDesk for fallback access, and moves laterally with a harvested domain administrator before the intrusion is contained pre-encryption. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h
8 tasks
50 points
Free

Launches in 5 days

Sep 29, 2026

Tuesday, September 29, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

XDRSIEMFirewallQuery

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Identify how attacker code first executed
3Recover the hidden loader's hash
4Classify the masquerading step
5Find the beacon's command-and-control domain
6Recover the harvested administrator
7Classify the fallback remote-access channel
8Trace the inbound operator address

Be first when it launches

Create your free account now. The moment this operation goes live on Sep 29, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free