logo

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

ID: e2e6b80d-645d-5b60-af90-8c8d4ed35d60

STIX ID: report--e2e6b80d-645d-5b60-af90-8c8d4ed35d60

Feed Name: The DFIR Report

Threat Score
80/100

Date Published: 2025-08-05

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR report describes a July 2025 SEO-poisoning campaign that served trojanized IT management installers (e.g., ManageEngine OpManager) to deliver the Bumblebee loader, allowing actors to gain privileged admin access, perform discovery and credential dumping (NTDS/LSASS), install remote access tools (RustDesk), exfiltrate data via SFTP, and deploy Akira ransomware across domains; the report includes detailed TTPs, detection/hunting guidance, and IOCs (domains, IPs, and hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.