logo

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

ID: d4e210b7-fc52-5d67-a9fc-6c5833a7357e

STIX ID: report--d4e210b7-fc52-5d67-a9fc-6c5833a7357e

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2025-11-04

Date Updated: 2026-04-19

Author: editor

...
...

A July 2025 SEO-poisoning campaign lured IT administrators to trojanized installers (e.g., ManageEngine-OpManager.msi) that side-loaded the Bumblebee loader (msimg32.dll), enabling AdaptixC2 access, rapid domain compromise (NTDS.dit dump, LSASS memory theft), persistence (RustDesk), SSH tunneling for proxying, data exfiltration via SFTP, and deployment of Akira ransomware across root and child domains; multiple IOCs (domains, IPs, and file hashes) and defensive hunting recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.