Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions

Summary
A DFIR investigation details two July 2025 intrusions linked to a BumbleBee SEO-poisoning campaign, tracing trojanized software downloads through AdaptixC2, credential theft and data exfiltration to Akira ransomware deployment.
Key points
- Attackers used Bing search results and look-alike software download sites to deliver BumbleBee through trojanized ManageEngine OpManager and Advanced IP Scanner installers.
- BumbleBee used DLL side-loading and deployed AdaptixC2; attackers also used RustDesk, SSH tunnels and Cloudflare tunneling for remote access and lateral movement.
- The intrusions involved privileged domain-account creation, NTDS.dit and LSASS credential dumping, and theft of Veeam credentials.
- Attackers exfiltrated about 77GB through FileZilla/SFTP; a separate transfer of about 2.5GB over SSH was also observed.
- The intrusions culminated in Akira ransomware deployment across servers and domain environments, with shadow-copy deletion to impede recovery.
- The report documents overlapping infrastructure and delivery patterns across BumbleBee campaign waves, alongside network, Sigma and YARA detection references.
Article Details
- Attack Vectors
- In July 2025, Bing SEO poisoning led a user searching for ManageEngine OpManager to a lookalike site and a trojanized MSI. An administrator later executed the installer from an internal network share.
- The MSI installed legitimate software as a decoy while staging consent.exe beside a malicious msimg32.dll, causing the BumbleBee loader to execute through DLL side-loading.
- BumbleBee injected Adaptix C2 shellcode into a renamed Windows Address Book executable. The threat actor then used administrative accounts, RDP, RustDesk, reverse SSH tunneling, and, in the Swisscom incident, a Cloudflare tunnel for continued access and movement.
- The threat actor harvested NTDS.dit, queried and decrypted stored Veeam credentials, and dumped LSASS memory. FileZilla SFTP sessions transferred data to an external server before Akira ransomware was deployed.
- A potentially related October 2025 Ivanti VPN-themed campaign used similar SEO-poisoning delivery infrastructure but distributed a VPN credential stealer rather than BumbleBee; the report notes operational differences and does not establish that it was the same campaign.
- Defensive Notes
- Investigate execution of relocated Windows binaries such as consent.exe from user-writable directories, particularly when a local msimg32.dll is loaded. The report says a System File Execution Location Anomaly Sigma rule triggered on this behavior.
- Correlate repeated BumbleBee DGA DNS queries with the C2 indicators in the report. The report also lists network detections for BumbleBee check-ins and responses.
- Monitor unexpected creation of privileged domain accounts, remote-access services, reverse SSH tunnels, encoded PowerShell, WMI-launched processes, and unusual RDP activity.
- Investigate comsvcs.dll MiniDump activity, NTDS.dit backups, Veeam credential queries, and outbound SFTP transfers. The report supplies Sigma and YARA detection references for several observed behaviors.
- In the Swisscom incident, potentially malicious or vulnerable drivers were registered as services in an apparent attempt to neutralize endpoint security controls; the report does not confirm that this attempt succeeded.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 2rxyt8yrhq0bgj[.]org | BumbleBee domain listed separately in the article's Atomic indicators; its spelling differs from the C2 narrative. |
| DOMAIN | 2rxyt9urhq0bgj[.]org | Domain identified in the article's C2 narrative as used for a successful BumbleBee connection. |
| DOMAIN | 5ka8rxp6t6eup2[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | 6cimu4mc085em8[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | 8doj8uvx604eck[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | d1hmxkpwby0d4s[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | download-center[.]online | Gateway that delivered the trojanized installer in the July 2025 intrusion. |
| DOMAIN | download-server[.]online | Wave 1 gateway hosting trojanized MSI installers. |
| DOMAIN | ev2sirbd269o5j[.]org | BumbleBee DGA domain used for a successful C2 connection. |
| DOMAIN | ewujsfb1dp5ran[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | ip-scanner[.]org | Advanced IP Scanner impersonation site used to lure a user in the Swisscom-linked intrusion. |
| DOMAIN | ks501oz9nm3v05[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | kwywztxoo2xdot[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | ky1d1p1daahe5t[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | netml[.]shop | Gateway attributed to the potentially related Ivanti VPN-themed credential-stealer campaign. |
| DOMAIN | opmanager[.]pro | Lookalike ManageEngine OpManager site used to lure the victim to a malicious installer. |
| DOMAIN | ovh1kn1tcqw5kp[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | shopping5[.]shop | Gateway attributed to the potentially related Ivanti VPN-themed credential-stealer campaign. |
| DOMAIN | soft-hub[.]pro | Wave 2 malicious download gateway. |
| DOMAIN | soft-server[.]online | Wave 1 malicious download gateway. |
| DOMAIN | v5rjsdqogstopr[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | yj6jurm5qqkye5[.]org | BumbleBee domain listed in the Atomic indicators. |
| DOMAIN | zenmap[.]pro | Malvertising impersonation front-end identified in the BumbleBee delivery operation. |
| IPV4 | 109[.]205[.]195[.]211 | BumbleBee C2 IP; a traffic spike also suggested it facilitated the Adaptix C2 payload download. |
| IPV4 | 170[.]130[.]55[.]223 | Outbound destination of the Adaptix C2 agent in the Swisscom-linked intrusion. |
| IPV4 | 171[.]22[.]183[.]43 | Additional IP contacted by BumbleBee during the intrusion. |
| IPV4 | 172[.]96[.]137[.]160 | Adaptix C2 beacon destination throughout the primary intrusion. |
| IPV4 | 185[.]174[.]100[.]203 | Threat actor-controlled SFTP exfiltration server contacted by FileZilla. |
| IPV4 | 188[.]40[.]187[.]145 | IP used for a successful BumbleBee C2 connection. |
| IPV4 | 192[.]121[.]22[.]94 | BumbleBee IP listed in the Atomic indicators. |
| IPV4 | 193[.]242[.]184[.]150 | Threat actor-controlled reverse SSH tunnel server that received approximately 2.5 GB from a domain controller. |
| IPV4 | 194[.]127[.]178[.]21 | BumbleBee IP listed in the Atomic indicators. |
| IPV4 | 4[.]239[.]95[.]1 | Hardcoded C2 IP to which the Ivanti-themed VPN credential stealer reportedly beaconed. |
| IPV4 | 84[.]32[.]84[.]32 | Staging IP shared by an Ivanti-themed gateway and the Wave 1 malicious gateway soft-server[.]online. |
| MD5 | 124a48b78060fa851e1cc077ca35713c | Hash listed for the malicious ManageEngine-OpManager.msi. |
| MD5 | 8c113b3aa82c81eee7c6b4ed0ba9a90f | Hash listed for the Akira ransomware binary staged as locker.exe. |
| MD5 | ca8646dfc88423bb9fffda811160cebe | Hash listed for the BumbleBee loader msimg32.dll. |
| SHA1 | ab82bf27132323861810c0efcac6d5dd01600dd4 | Hash listed for the malicious ManageEngine-OpManager.msi. |
| SHA1 | d66944e1a57daf04d3e809f22cd01946d593acaf | Hash listed for the Akira ransomware binary staged as locker.exe. |
| SHA1 | febbaf5f08a8e0782ffcce8beef1f2b4e249a52b | Hash listed for the BumbleBee loader msimg32.dll. |
| SHA256 | 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da | Hash listed for the malicious ManageEngine-OpManager.msi. |
| SHA256 | a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331 | Hash listed for the BumbleBee loader msimg32.dll. |
| SHA256 | de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d | Hash listed for the Akira ransomware binary staged as locker.exe. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThe threat actor used comsvcs.dll MiniDump-based activity consistent with lsassy to dump LSASS on multiple hosts.T1003.003 · NTDSwbadmin.exe backed up NTDS.dit with the SYSTEM and SECURITY hives for offline credential harvesting.T1018 · Remote System DiscoveryThe threat actor used pings, domain-controller queries, and network scans to identify internal systems.T1021.001 · Remote Desktop ProtocolRDP sessions enabled movement from the beachhead to domain controllers and other servers.T1021.003 · Distributed Component Object ModelRemote LSASS-dumping attempts included execution through the MMC20.Application DCOM object.T1027.010 · Command ObfuscationThe threat actor used mixed-case command invocations and an encoded PowerShell command.T1033 · System Owner/User DiscoveryThe threat actor used whoami and quser to identify users and sessions.T1036 · MasqueradingTrojanized installers deployed legitimate applications as decoys, and the Adaptix C2 host executable was disguised as a renamed Windows utility.T1039 · Data from Network Shared DriveThe threat actor accessed network shares and likely exfiltrated SYSVOL data.T1041 · Exfiltration Over C2 ChannelApproximately 2.5 GB was transferred to the threat actor-controlled reverse SSH tunnel server.T1046 · Network Service DiscoveryThe Adaptix C2 process and SoftPerfect Network Scanner scanned internal hosts and services.T1047 · Windows Management InstrumentationWMI launched the Adaptix C2 host process and was used for remote execution and shadow-copy deletion.T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 ProtocolFileZilla used encrypted SFTP sessions to transfer data to an external exfiltration server.T1055 · Process InjectionBumbleBee injected Adaptix C2 shellcode into the renamed Windows Address Book process.T1059.001 · PowerShellPowerShell scripts enumerated Active Directory data, decrypted credentials, and deleted shadow copies.T1059.003 · Windows Command ShellThe threat actor issued discovery and execution commands through cmd.exe.T1069.001 · Local GroupsThe threat actor ran net localgroup commands to enumerate local groups.T1069.002 · Domain GroupsThe threat actor queried domain administrative groups and group memberships.T1070.004 · File DeletionHost telemetry showed deletion of local attack components and reconnaissance logs.T1071.001 · Web ProtocolsThe injected Adaptix C2 agent established an HTTP beacon.T1082 · System Information DiscoveryThe threat actor ran systeminfo on multiple hosts.T1083 · File and Directory DiscoveryThe threat actor inspected directories and enumerated files and shares before exfiltration.T1087.001 · Local AccountThe threat actor queried local administrator and other local accounts on servers.T1087.002 · Domain AccountThe threat actor enumerated domain user accounts with net commands and Get-ADUser.T1090 · ProxyA reverse SSH tunnel proxied internal RDP traffic through an external server.T1135 · Network Share DiscoveryInvoke-ShareFinder enumerated accessible SMB shares.T1136 · Create AccountThe threat actor created the backup_DA and backup_EA domain accounts for continued access.T1204.002 · Malicious FileAn administrator manually launched the trojanized ManageEngine-OpManager.msi.T1219 · Remote Access ToolsThe threat actor installed and used RustDesk for interactive remote access.T1482 · Domain Trust DiscoveryThe threat actor ran nltest /domain_trusts during internal discovery.T1486 · Data Encrypted for ImpactAkira ransomware encrypted servers and network-accessible resources.T1490 · Inhibit System RecoveryAkira invoked PowerShell through WMI to delete Volume Shadow Copies.T1543.003 · Windows ServiceThe threat actor registered RustDesk as a Windows service; the Swisscom incident also involved a Cloudflare tunneling service.T1555 · Credentials from Password StoresThe threat actor queried stored Veeam credentials and used a PowerShell script to decrypt them.T1568.002 · Domain Generation AlgorithmsBumbleBee queried dynamically generated domains for C2 communication.T1569.002 · Service ExecutionRemote LSASS-dumping attempts included service creation through SMB svcctl.T1574.001 · DLLA relocated consent.exe loaded the attacker's local msimg32.dll, executing the BumbleBee loader.
People
Ahmed FaroukCredited with analysis and reporting.Angelo ViolettiCredited with reviewing the report.DinoCredited with analysis and reporting.hasherezadeIdentified as the malware analyst who developed PE-sieve, used in the report's controlled analysis.JakeCredited with analysis and reporting.Mattison SchuchCredited with analysis and reporting.Renzon CruzCredited with reviewing the report.
Malware
Vendors
Cloudflareobserved intrusion, the threat actor achieved persistence on a domain controller by installing the Cloudflare tunneling software as a Windows service, causing it to run automatically after the host rebooted.ManageEngineIn July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager.SoftPerfectthreat actor again logged into the domain controller, executed discovery commands, and then dropped a SoftPerfect Network Scanner binary (n.exe), which was executed to perform a network scan.VeeamThey engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI.
Products
Advanced IP Scanner(July 2025) Tools Targeted WinMTR, Zenmap, RVTools, Milestone XProtect ManageEngine OpManager, Advanced IP Scanner, MIB Browser Download Gateways download-server[.]online ,soft-server[.]onlineFileZillaThe threat actor returned the following day and established an SSH proxy, enabling lateral movement across the network and data exfiltration via FileZilla and SFTP to an external server.Ivanti VPNIn October 2025, Zscaler documented a parallel campaign targeting user searching for Ivanti VPN.ManageEngine OpManagerIn July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager.RustDeskTo ensure persistence, the threat actor created new domain accounts with Enterprise Admin privileges and installed RustDesk as a Windows service on multiple servers.VeeamThey engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI.
Tools
AdaptixC2Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit.ImpacketUnder the hood, lsassy leverages the Impacket library for remote orchestration.Invoke-ShareFinderShortly after, Invoke-Sharefinder was executed to enumerate accessible SMB shares.lsassyThe threat actor also employed the lsassy utility to dump LSASS memory across multiple hosts.PE-sieveDuring runtime, the memory analysis tool PE-sieve, developed by the malware analyst hasherezade, was executed against the live consent.exe process.PEStudioStatic analysis using PEStudio confirmed that msimg32.dll is a legitimate, expected dependency of the consent.exe binary.PowerSploitIt was originally developed as part of the PowerView module within the PowerSploit framework, but has since been integrated into numerous offensive projects.PowerViewIt was originally developed as part of the PowerView module within the PowerSploit framework, but has since been integrated into numerous offensive projects.SigmaThe Sigma rule System File Execution Location Anomaly was triggered since it looks for execution of commonly abused Windows built-in binaries (consent.exe) outside of their normal path; in this case, the binary executedSoftPerfect Network Scanneractor again logged into the domain controller, executed discovery commands, and then dropped a SoftPerfect Network Scanner binary (n.exe), which was executed to perform a network scan.SysmonThis hijacked execution flow was corroborated by Sysmon event logs, which captured the anomalous process creation and image loading.YARAThey are extremely useful as a YARA signature because the strings collide essentially nowhere in benign software.ZeekAnalysis of Zeek logs show that roughly 77GB of data was transferred out of the victim network via two unique sessions originating from FileZilla.