Bing Search Poisoning Led to Bumblebee Infection and Akira Ransomware

Summary
A July 2025 SEO-poisoning campaign delivered Bumblebee through trojanized IT-tool installers, enabling attackers to steal credentials, exfiltrate data, and deploy Akira ransomware across enterprise domains.
Key points
- A Bing search for ManageEngine OpManager led a user to a malicious site and a trojanized MSI that installed Bumblebee.
- Attackers used privileged IT administrator accounts to move laterally, create elevated domain accounts, dump domain credentials, and install RustDesk for persistence.
- They deployed AdaptixC2, tunneled activity over SSH, stole data via SFTP, and attempted to extract credentials from a Veeam PostgreSQL database.
- Akira ransomware was deployed across the root domain about 44 hours after initial access; attackers returned two days later to encrypt systems in a child domain.
- The report describes a similar Bumblebee-to-Akira intrusion handled by Swisscom B2B CSIRT, with ransomware deployed in nine hours.
- The article provides hunting guidance for trojanized MSI installs, Bumblebee DGA activity, credential dumping, domain enumeration, remote-access tools, and suspicious account creation.
Article Details
- Attack Vectors
- A Bing search for ManageEngine OpManager led a user to opmanager[.]pro, where they downloaded a trojanized MSI installer.
- The installer installed legitimate software while loading Bumblebee through consent.exe. Bumblebee later deployed an AdaptixC2 beacon.
- The threat actor used newly created privileged domain accounts, remote access, credential dumping, and lateral movement before deploying Akira ransomware in the root domain and, two days later, a child domain.
- Defensive Notes
- Investigate MSI installations from user directories that spawn unexpected processes such as consent.exe or load msimg32.dll.
- Monitor for rapid domain enumeration, creation of privileged backup accounts, RDP logons using those accounts, and wbadmin backups of NTDS.dit and registry hives.
- Hunt for LSASS dumps using rundll32.exe and comsvcs.dll, SSH reverse tunnels, and FileZilla installations on servers followed by large outbound transfers.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 2rxyt9urhq0bgj[.]org | Bumblebee DGA domain listed as an indicator. |
| DOMAIN | angryipscanner[.]org | Site identified by The DFIR Report as distributing a trojanized installer. |
| DOMAIN | axiscamerastation[.]org | Site identified by The DFIR Report as distributing a trojanized installer. |
| DOMAIN | ev2sirbd269o5j[.]org | Bumblebee DGA domain listed as an indicator. |
| DOMAIN | ijt0l3i8brit6q[.]org | Example Bumblebee DGA domain in the hunting guidance. |
| DOMAIN | ip-scanner[.]org | Site identified by Swisscom B2B CSIRT as distributing a trojanized installer. |
| DOMAIN | opmanager[.]pro | Malicious site that delivered a trojanized ManageEngine OpManager installer. |
| IPV4 | 109[.]205[.]195[.]211 | Bumblebee C2 address. |
| IPV4 | 170[.]130[.]55[.]223 | AdaptixC2 C2 address reported by Swisscom B2B CSIRT. |
| IPV4 | 172[.]96[.]137[.]160 | AdaptixC2 C2 address reported by The DFIR Report. |
| IPV4 | 185[.]174[.]100[.]203 | SFTP server used for data exfiltration. |
| IPV4 | 188[.]40[.]187[.]145 | Bumblebee C2 address. |
| IPV4 | 193[.]242[.]184[.]150 | External SSH tunnel host reported by The DFIR Report. |
| IPV4 | 83[.]229[.]17[.]60 | External SSH tunnel host reported by Swisscom B2B CSIRT. |
| SHA256 | 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da | Malicious ManageEngine-OpManager.msi installer reported by The DFIR Report. |
| SHA256 | 18b8e6762afd29a09becae283083c74a19fc09db1f2c3412c42f1b0178bc122a | Akira ransomware win.exe reported by Swisscom B2B CSIRT. |
| SHA256 | 6ba5d96e52734cbb9246bcc3decf127f780d48fa11587a1a44880c1f04404d23 | Bumblebee msimg32.dll reported by Swisscom B2B CSIRT. |
| SHA256 | a14506c6fb92a5af88a6a44d273edafe10d69ee3d85c8b2a7ac458a22edf68d2 | Malicious Advanced-IP-Scanner.msi installer reported by Swisscom B2B CSIRT. |
| SHA256 | a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331 | Bumblebee msimg32.dll reported by The DFIR Report. |
| SHA256 | de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d | Akira ransomware locker.exe reported by The DFIR Report. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThe threat actor dumped LSASS memory on multiple workstations using rundll32.exe and comsvcs.dll.T1003.003 · NTDSThe threat actor used wbadmin.exe to back up NTDS.dit and registry hives from a domain controller.T1021.001 · Remote Desktop ProtocolThe threat actor connected to a domain controller via RDP using backup_EA.T1046 · Network Service DiscoveryThe threat actor deployed a renamed SoftPerfect network scanner for internal discovery.T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolThe threat actor used FileZilla to exfiltrate data via SFTP to an external server.T1078.002 · Domain AccountsThe threat actor used the newly created privileged backup_EA domain account to connect to a domain controller.T1136.002 · Domain AccountThe threat actor created domain accounts backup_DA and backup_EA.T1204.002 · Malicious FileA user downloaded and executed a trojanized ManageEngine-OpManager.msi installer.T1219 · Remote Access ToolsThe threat actor installed RustDesk on several hosts for persistence and later returned through it.T1486 · Data Encrypted for ImpactThe threat actor deployed Akira to encrypt systems in the root domain and later the child domain.T1568.002 · Domain Generation AlgorithmsBumblebee used DGA domains for command and control.T1572 · Protocol TunnelingThe threat actor established an SSH reverse tunnel to an external server to proxy activity.T1574.002 · DLL Side-LoadingThe trojanized installer loaded Bumblebee as msimg32.dll through consent.exe while installing legitimate software.T1608.006 · SEO PoisoningThe campaign used SEO poisoning to lead searches for IT management software to malicious installer sites.
Malware
Products
Angry IP ScannerDuring our investigation of the OpManager site, we identified two additional websites that appear to be distributing trojanized installers for Axis Camera tools and Angry IP Scanner.BingThis intrusion began when a user, searching for “ManageEngine OpManager” on Bing, was directed to the malicious site opmanager[.]pro.FileZillaAround the same time, the threat actor installed FileZilla on a file server and exfiltrated data via SFTP to 185.174.100[.]203.ManageEngine OpManagerA user searching for “ManageEngine OpManager” was directed to a malicious website, which delivered a trojanized software installer.RustDeskFor persistence and re-entry, the threat actor installed the RustDesk remote access tool on several hosts.
Tools
AdaptixC2Approximately five hours after this initial execution, Bumblebee deployed an AdaptixC2 beacon (AdgNsy.exe), which established a new C2 channel to 172.96.137[.]160:443.Invoke-ShareFinderRustDesk, connected to a child domain controller, and performed another round of discovery using Invoke-ShareFinder and DNS zone export commands, before deploying Akira ransomware to the child domain.SoftPerfect Network ScannerThey continued discovery by deploying a renamed SoftPerfect network scanner (n.exe).