Bing Search Poisoning Led to Bumblebee Infection and Akira Ransomware

· Original article ↗

Summary

A July 2025 SEO-poisoning campaign delivered Bumblebee through trojanized IT-tool installers, enabling attackers to steal credentials, exfiltrate data, and deploy Akira ransomware across enterprise domains.

Key points

  • A Bing search for ManageEngine OpManager led a user to a malicious site and a trojanized MSI that installed Bumblebee.
  • Attackers used privileged IT administrator accounts to move laterally, create elevated domain accounts, dump domain credentials, and install RustDesk for persistence.
  • They deployed AdaptixC2, tunneled activity over SSH, stole data via SFTP, and attempted to extract credentials from a Veeam PostgreSQL database.
  • Akira ransomware was deployed across the root domain about 44 hours after initial access; attackers returned two days later to encrypt systems in a child domain.
  • The report describes a similar Bumblebee-to-Akira intrusion handled by Swisscom B2B CSIRT, with ransomware deployed in nine hours.
  • The article provides hunting guidance for trojanized MSI installs, Bumblebee DGA activity, credential dumping, domain enumeration, remote-access tools, and suspicious account creation.

Article Details

Attack Vectors
  • A Bing search for ManageEngine OpManager led a user to opmanager[.]pro, where they downloaded a trojanized MSI installer.
  • The installer installed legitimate software while loading Bumblebee through consent.exe. Bumblebee later deployed an AdaptixC2 beacon.
  • The threat actor used newly created privileged domain accounts, remote access, credential dumping, and lateral movement before deploying Akira ransomware in the root domain and, two days later, a child domain.
Defensive Notes
  • Investigate MSI installations from user directories that spawn unexpected processes such as consent.exe or load msimg32.dll.
  • Monitor for rapid domain enumeration, creation of privileged backup accounts, RDP logons using those accounts, and wbadmin backups of NTDS.dit and registry hives.
  • Hunt for LSASS dumps using rundll32.exe and comsvcs.dll, SSH reverse tunnels, and FileZilla installations on servers followed by large outbound transfers.

Indicators of compromise

TypeIndicatorContext
DOMAIN2rxyt9urhq0bgj[.]orgBumblebee DGA domain listed as an indicator.
DOMAINangryipscanner[.]orgSite identified by The DFIR Report as distributing a trojanized installer.
DOMAINaxiscamerastation[.]orgSite identified by The DFIR Report as distributing a trojanized installer.
DOMAINev2sirbd269o5j[.]orgBumblebee DGA domain listed as an indicator.
DOMAINijt0l3i8brit6q[.]orgExample Bumblebee DGA domain in the hunting guidance.
DOMAINip-scanner[.]orgSite identified by Swisscom B2B CSIRT as distributing a trojanized installer.
DOMAINopmanager[.]proMalicious site that delivered a trojanized ManageEngine OpManager installer.
IPV4109[.]205[.]195[.]211Bumblebee C2 address.
IPV4170[.]130[.]55[.]223AdaptixC2 C2 address reported by Swisscom B2B CSIRT.
IPV4172[.]96[.]137[.]160AdaptixC2 C2 address reported by The DFIR Report.
IPV4185[.]174[.]100[.]203SFTP server used for data exfiltration.
IPV4188[.]40[.]187[.]145Bumblebee C2 address.
IPV4193[.]242[.]184[.]150External SSH tunnel host reported by The DFIR Report.
IPV483[.]229[.]17[.]60External SSH tunnel host reported by Swisscom B2B CSIRT.
SHA256186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5daMalicious ManageEngine-OpManager.msi installer reported by The DFIR Report.
SHA25618b8e6762afd29a09becae283083c74a19fc09db1f2c3412c42f1b0178bc122aAkira ransomware win.exe reported by Swisscom B2B CSIRT.
SHA2566ba5d96e52734cbb9246bcc3decf127f780d48fa11587a1a44880c1f04404d23Bumblebee msimg32.dll reported by Swisscom B2B CSIRT.
SHA256a14506c6fb92a5af88a6a44d273edafe10d69ee3d85c8b2a7ac458a22edf68d2Malicious Advanced-IP-Scanner.msi installer reported by Swisscom B2B CSIRT.
SHA256a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331Bumblebee msimg32.dll reported by The DFIR Report.
SHA256de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19dAkira ransomware locker.exe reported by The DFIR Report.

MITRE ATT&CK

T1003.001 · LSASS MemoryThe threat actor dumped LSASS memory on multiple workstations using rundll32.exe and comsvcs.dll.T1003.003 · NTDSThe threat actor used wbadmin.exe to back up NTDS.dit and registry hives from a domain controller.T1021.001 · Remote Desktop ProtocolThe threat actor connected to a domain controller via RDP using backup_EA.T1046 · Network Service DiscoveryThe threat actor deployed a renamed SoftPerfect network scanner for internal discovery.T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolThe threat actor used FileZilla to exfiltrate data via SFTP to an external server.T1078.002 · Domain AccountsThe threat actor used the newly created privileged backup_EA domain account to connect to a domain controller.T1136.002 · Domain AccountThe threat actor created domain accounts backup_DA and backup_EA.T1204.002 · Malicious FileA user downloaded and executed a trojanized ManageEngine-OpManager.msi installer.T1219 · Remote Access ToolsThe threat actor installed RustDesk on several hosts for persistence and later returned through it.T1486 · Data Encrypted for ImpactThe threat actor deployed Akira to encrypt systems in the root domain and later the child domain.T1568.002 · Domain Generation AlgorithmsBumblebee used DGA domains for command and control.T1572 · Protocol TunnelingThe threat actor established an SSH reverse tunnel to an external server to proxy activity.T1574.002 · DLL Side-LoadingThe trojanized installer loaded Bumblebee as msimg32.dll through consent.exe while installing legitimate software.T1608.006 · SEO PoisoningThe campaign used SEO poisoning to lead searches for IT management software to malicious installer sites.

Malware

Products

Tools

Related Articles