
Mounted and Loaded: ISO Container Delivery of the Bumblebee Loader
An ISO image attachment hides a visible shortcut beside a hidden DLL. The user mounts the container and runs the shortcut, which executes the Bumblebee loader via rundll32 against a DLL export. Bumblebee injects into a signed Windows Mail binary through WMI, beacons HTTPS to a C2 cluster, then layers a Meterpreter stager and a Cobalt Strike beacon. The operator runs AdFind discovery, dumps LSASS with ProcDump, creates a rogue local admin, installs AnyDesk for fallback access, and moves laterally with a harvested domain administrator before the intrusion is contained pre-encryption. Reconstruct the kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.
Launches in 5 days
Tuesday, September 29, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
8 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Sep 29, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free