From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
ID: e2e6b80d-645d-5b60-af90-8c8d4ed35d60
STIX ID: report--e2e6b80d-645d-5b60-af90-8c8d4ed35d60
Feed Name: The DFIR Report
This DFIR report describes a July 2025 SEO-poisoning campaign that served trojanized IT management installers (e.g., ManageEngine OpManager) to deliver the Bumblebee loader, allowing actors to gain privileged admin access, perform discovery and credential dumping (NTDS/LSASS), install remote access tools (RustDesk), exfiltrate data via SFTP, and deploy Akira ransomware across domains; the report includes detailed TTPs, detection/hunting guidance, and IOCs (domains, IPs, and hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
