LIVE · cybersecurity feed
Live wire
bumblebeehigh

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

A sophisticated cyberattack campaign, identified in July 2025, leveraged SEO poisoning to trick users searching for ManageEngine OpManager into downloading a trojanized installer. This led to the deployment of Bumblebee malware, which then established a command-and-control channel using AdaptixC2. The attackers exploited this access for credential harvesting, lateral movement, and ultimately deployed Akira ransomware across the victim's network.

zeroday.news · 33d ago

In July 2025, a targeted cyberattack campaign initiated through SEO poisoning successfully compromised a network by luring a user searching for "ManageEngine OpManager" to a fraudulent website. This site delivered a trojanized installer, which, upon execution, deployed the Bumblebee malware. The initial infection was facilitated by a malicious MSI installer, executed by an IT administrator who was deceived by a convincing look-alike domain.

Following initial access, Bumblebee established command-and-control (C2) communication using a component known as AdaptixC2. This allowed the threat actors to map the internal network using legitimate Windows tools and gain further access. The attackers demonstrated a clear objective to escalate privileges, creating new domain accounts with Enterprise Admin rights and installing remote access tools like RustDesk on multiple servers.

The attackers then moved laterally within the network, targeting a domain controller and a backup server. They employed advanced techniques for credential harvesting, including extracting the NTDS.dit Active Directory database and decrypting Veeam backup credentials. Tools like lsassy were used to dump LSASS memory, further aiding in credential acquisition.

Defense evasion and stealth were key components of the attack. The threat actors utilized reverse SSH tunnels to bypass firewall restrictions and employed obfuscation techniques for command-line arguments. In one instance, a Bring Your Own Vulnerable Driver (BYOVD) attack was used to disable endpoint security controls, highlighting a multi-faceted approach to evading detection.

Data exfiltration was conducted using FileZilla, with over 75GB of sensitive data, including file shares and domain configurations, being transferred to a server controlled by the attackers. The operation concluded with the deployment of Akira ransomware, which was used to encrypt critical systems after Volume Shadow Copies were deleted to prevent easy recovery.

This campaign is part of a broader pattern of Bumblebee SEO poisoning attacks observed since May 2025, which consistently use a two-tier delivery architecture involving impersonation front-ends and universal delivery gateways. These attacks have targeted various enterprise software, including WinMTR, Zenmap, and Ivanti VPN, often utilizing shared infrastructure and code-signing certificates.

Analysis of the infrastructure revealed overlap with other campaigns, including one targeting Ivanti VPN users, which also employed SEO poisoning and similar delivery mechanics. However, the Ivanti campaign differed in its payload and signature attribution, suggesting a coordinated but potentially evolving threat landscape.

The intrusion was first reported to customers in July 2025 and publicly disclosed in August 2025 in partnership with Swisscom B2B CSIRT, which observed a related intrusion. The detailed analysis of these incidents provides valuable insights into the tactics, techniques, and procedures employed by these threat actors.

bumblebeeadaptixc2akira ransomwareseo poisoningmanageengine
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.