Bumblebee and AdaptixC2 Deliver Akira Ransomware via SEO Poisoning
Score: 10/10

Bumblebee and AdaptixC2 Deliver Akira Ransomware via SEO Poisoning

Akira ransomware actors utilized Bumblebee malware and AdaptixC2 via Bing SEO poisoning to gain initial access, move laterally, and exfiltrate over 75GB of data.

Executive Summary

In a series of intrusions observed between May and July 2025, threat actors successfully deployed Akira ransomware by first gaining access through a Bumblebee SEO poisoning campaign. The attack targeted IT administrators searching for legitimate tools like 'ManageEngine OpManager' and 'Advanced IP Scanner,' redirecting them to look-alike domains serving trojanized MSI installers. Once executed, the Bumblebee loader facilitated the deployment of the AdaptixC2 framework for persistent command-and-control.

The technical execution involved sophisticated defense evasion, including DLL side-loading of a malicious `msimg32.dll` via the legitimate Windows `consent.exe` and a Bring Your Own Vulnerable Driver (BYOVD) attack to neutralize security software. The actors moved laterally using RDP and SSH tunneling, eventually harvesting credentials from NTDS.dit and Veeam databases. The campaign culminated in the exfiltration of sensitive data to servers in Ukraine followed by domain-wide encryption using Akira ransomware.

This threat highlights the ongoing risk of search-based malware delivery targeting high-privilege IT staff. The speed of the intrusion, with ransomware deployment occurring within 44 hours of initial access, necessitates rapid detection of early-stage indicators like anomalous built-in Windows binary execution and unauthorized remote access tools like RustDesk.

Key Details

Threat Name

Akira Ransomware Campaign

Affects

—

Adversary

Akira

Malware/Tools

Akira, BumbleBee, AdaptixC2, lsassy, SoftPerfect Network Scanner, Invoke-Sharefinder

Report Score

10out of 10
Quality Score
Excellent
IOC Quality10
TTP Details10
Detection Guidance9
Enterprise Relevance10
Clarity & Structure10
Technical Depth10

Sources