Cyber Security News

Threat Actors Deliver Bumblebee Malware Poisoning Bing SEO

A sophisticated malware campaign leveraging search engine optimization (SEO) poisoning on Microsoft Bing has emerged, delivering the notorious Bumblebee malware to unsuspecting users.

The campaign, identified in May 2025, specifically targets users searching for specialized software tools, demonstrating a concerning evolution in malware distribution tactics that exploits trusted search engine results.

Bumblebee, a downloader malware first discovered in 2022, has been linked to ransomware operations due to its developer’s connections with the Conti group.

The malware has gained notoriety for its effectiveness and has been delivered through various methods including phishing emails, malicious documents, and now SEO poisoning campaigns.

In this latest attack vector, threat actors have created convincing duplicate websites for legitimate software packages, successfully manipulating Bing’s search algorithms to position these malicious sites at the top of search results.

Cyjax researchers identified the campaign after discovering a series of fake download websites targeting users searching for specific software packages.

The current campaign focuses on two specialized software tools: WinMTR, an open-source network diagnostic tool, and Milestone XProtect, a video management software used for surveillance systems.

Malicious sites appear as the top result (Source – CYJAX)

Both legitimate applications are popular within technical and security environments, suggesting a potential focus on targeting developer and IT professional systems.

The attack employs a sophisticated domain typosquatting technique where domains closely resembling legitimate ones are registered.

For instance, the legitimate domain “winmtr.net” is spoofed by “winmtr.org,” while “milestonesys.com” is mimicked by “milestonesys.org.”

Both malicious domains are hosted on the same server owned by Truehost Cloud in Nairobi, indicating a coordinated campaign by a single threat actor group.

Infection Mechanism Analysis

The infection process begins when users click download links on the spoofed websites. The malicious MSI installers, hosted on an external domain called “software-server[.]online,” are then delivered to the victim’s system.

Bumblebee execution flow (Source – CYJAX)

When executed via msiexec[.]exe, the installer delivers both the legitimate application (such as winmtr.exe) and malicious components, including a legitimate-appearing Windows binary called icardagt.exe and a malicious DLL named version.dll.

The execution flow, as shown in Figure 1, demonstrates how the malware maintains stealth by running the legitimate application while simultaneously loading the malicious DLL.

The icardagt.exe executable, despite using an expired certificate from January 2010, loads version.dll, which then executes the Bumblebee malware. Once activated, Bumblebee establishes connections to numerous command and control (C2) domains, all using the “.life” top-level domain (TLD).

This campaign represents a significant shift from previous Bumblebee SEO poisoning efforts that targeted more widely recognized software like Zoom, Cisco AnyConnect, and ChatGPT installers.

The pivot to more obscure technical tools suggests an intentional targeting of environments where users may have elevated privileges, creating ideal conditions for further network compromise or information theft.

Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago