Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da

TLP:CLEAR
Active

SHA-256 Hash

Description

In July 2025, threat actors compromised organizations through SEO poisoning campaigns targeting users searching for legitimate IT management tools. Users downloading trojanized installers for ManageEngine OpManager received Bumblebee malware, granting initial access. The attackers exploited the fact that users executing these IT tools were privileged administrators, enabling rapid lateral movement to domain controllers. They dumped credentials using wbadmin, created backdoor accounts with enterprise admin privileges, and installed RustDesk for persistent access. AdaptixC2 beacons were deployed for command and control. The threat actors conducted extensive reconnaissance, dumped LSASS memory across multiple systems, attempted Veeam credential theft, and exfiltrated data via SFTP using FileZilla. The intrusion culminated in Akira ransomware deployment across both root and child domains within 44 hours, with subsequent re-encryption two days later affecting the child domain.

Sightings (0)

No sightings recorded yet

Details

Name / Label
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Pattern Type
STIX
Confidence
75%
Valid From
Jul 5, 2026 15:12
Total Sightings
0
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.