logo

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

ID: 396a1326-24d2-5a79-ae00-92c9d6233758

STIX ID: report--396a1326-24d2-5a79-ae00-92c9d6233758

Feed Name: The DFIR Report

Threat Score
85/100

Date Published: 2026-06-29

Date Updated: 2026-07-02

Author: editor

...
...

In July 2025 a BumbleBee SEO‑poisoning campaign delivered trojanized ManageEngine OpManager installers to IT staff, leading to DLL side‑loading of a BumbleBee loader, deployment of an AdaptixC2 beacon, extensive credential harvesting (NTDS.dit, LSASS, Veeam), lateral movement via RDP and reverse SSH tunnels, exfiltration of ~77 GB via SFTP (FileZilla) to an external server, and culminated with Akira ransomware encrypting root and child domains; the report provides technical analysis, IOCs (domains, IPs, hashes), MITRE ATT&CK mappings, and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.