Executive Summary
In a series of intrusions observed between May and July 2025, threat actors successfully deployed Akira ransomware by first gaining access through a Bumblebee SEO poisoning campaign. The attack targeted IT administrators searching for legitimate tools like 'ManageEngine OpManager' and 'Advanced IP Scanner,' redirecting them to look-alike domains serving trojanized MSI installers. Once executed, the Bumblebee loader facilitated the deployment of the AdaptixC2 framework for persistent command-and-control.
The technical execution involved sophisticated defense evasion, including DLL side-loading of a malicious `msimg32.dll` via the legitimate Windows `consent.exe` and a Bring Your Own Vulnerable Driver (BYOVD) attack to neutralize security software. The actors moved laterally using RDP and SSH tunneling, eventually harvesting credentials from NTDS.dit and Veeam databases. The campaign culminated in the exfiltration of sensitive data to servers in Ukraine followed by domain-wide encryption using Akira ransomware.
This threat highlights the ongoing risk of search-based malware delivery targeting high-privilege IT staff. The speed of the intrusion, with ransomware deployment occurring within 44 hours of initial access, necessitates rapid detection of early-stage indicators like anomalous built-in Windows binary execution and unauthorized remote access tools like RustDesk.
