From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
ID: 396a1326-24d2-5a79-ae00-92c9d6233758
STIX ID: report--396a1326-24d2-5a79-ae00-92c9d6233758
Feed Name: The DFIR Report
In July 2025 a BumbleBee SEO‑poisoning campaign delivered trojanized ManageEngine OpManager installers to IT staff, leading to DLL side‑loading of a BumbleBee loader, deployment of an AdaptixC2 beacon, extensive credential harvesting (NTDS.dit, LSASS, Veeam), lateral movement via RDP and reverse SSH tunnels, exfiltration of ~77 GB via SFTP (FileZilla) to an external server, and culminated with Akira ransomware encrypting root and child domains; the report provides technical analysis, IOCs (domains, IPs, hashes), MITRE ATT&CK mappings, and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
