In July 2025, a targeted cyberattack campaign initiated through SEO poisoning successfully compromised a network by luring a user searching for "ManageEngine OpManager" to a fraudulent website. This site delivered a trojanized installer, which, upon execution, deployed the Bumblebee malware. The initial infection was facilitated by a malicious MSI installer, executed by an IT administrator who was deceived by a convincing look-alike domain.
Following initial access, Bumblebee established command-and-control (C2) communication using a component known as AdaptixC2. This allowed the threat actors to map the internal network using legitimate Windows tools and gain further access. The attackers demonstrated a clear objective to escalate privileges, creating new domain accounts with Enterprise Admin rights and installing remote access tools like RustDesk on multiple servers.
The attackers then moved laterally within the network, targeting a domain controller and a backup server. They employed advanced techniques for credential harvesting, including extracting the NTDS.dit Active Directory database and decrypting Veeam backup credentials. Tools like lsassy were used to dump LSASS memory, further aiding in credential acquisition.
Defense evasion and stealth were key components of the attack. The threat actors utilized reverse SSH tunnels to bypass firewall restrictions and employed obfuscation techniques for command-line arguments. In one instance, a Bring Your Own Vulnerable Driver (BYOVD) attack was used to disable endpoint security controls, highlighting a multi-faceted approach to evading detection.
Data exfiltration was conducted using FileZilla, with over 75GB of sensitive data, including file shares and domain configurations, being transferred to a server controlled by the attackers. The operation concluded with the deployment of Akira ransomware, which was used to encrypt critical systems after Volume Shadow Copies were deleted to prevent easy recovery.
This campaign is part of a broader pattern of Bumblebee SEO poisoning attacks observed since May 2025, which consistently use a two-tier delivery architecture involving impersonation front-ends and universal delivery gateways. These attacks have targeted various enterprise software, including WinMTR, Zenmap, and Ivanti VPN, often utilizing shared infrastructure and code-signing certificates.
Analysis of the infrastructure revealed overlap with other campaigns, including one targeting Ivanti VPN users, which also employed SEO poisoning and similar delivery mechanics. However, the Ivanti campaign differed in its payload and signature attribution, suggesting a coordinated but potentially evolving threat landscape.
The intrusion was first reported to customers in July 2025 and publicly disclosed in August 2025 in partnership with Swisscom B2B CSIRT, which observed a related intrusion. The detailed analysis of these incidents provides valuable insights into the tactics, techniques, and procedures employed by these threat actors.






