Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373) — Threadlinqs Intelligence
As of 2026-07-06, Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373) is a critical-severity ransomware threat attributed to Akira (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 58 indicators of compromise.
Threat ID: TL-2026-1135 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: Akira · Russia · FINANCIAL
A Bing SEO-poisoning campaign lured users searching for "ManageEngine OpManager," "Advanced IP Scanner," and "Zenmap" to lookalike domains serving a trojanized MSI that side-loaded the Bumblebee
The DFIR Report (cases TB36726/PR40373, published 2026-06-29) documents a full intrusion chain that began with SEO poisoning of Bing search results for legitimate IT administration and network-scanning tools. Victims searching for "ManageEngine OpManager," "Advanced IP Scanner," and "Zenmap" were funneled through a two-tier infrastructure: impersonation front-end domains (opmanager.pro, ip-scanner.org, zenmap.pro) that redirected to backend delivery gateways (download-center.online, soft-server.online, soft-hub.pro) hosting a trojanized ManageEngine-OpManager.msi signed with a since-revoked "LLC Resource+" certificate.
Executing the MSI dropped files into %TEMP%\ApplicationInstallationFolder_11 and launched the legitimate Windows UAC binary consent.exe, which was hijacked via DLL search-order abuse to load a malicious msimg32.dll -- the Bumblebee loader. Bumblebee performed CIS-region locale geofencing (exiting on 27 excluded locales) before beaconing to a rotating set of 14-character .org DGA domains and hardcoded IPs. Approximately five hours after initial execution, Bumblebee dropped AdgNsy.exe (renamed as WAB.exe, the legitimate Windows Address Book utility) which was reflectively injected with AdaptixC2 shellcode via WmiPrvSE.exe, establishing a beacon to 172.96.137.160 (Shock Hosting) using AdaptixC2's default RC4-encrypted HTTP beacon profile.
Over the following days the actor conducted extensive discovery (whoami, systeminfo, quser, nltest /dclist, nltest /domain_trusts, SPN enumeration, Invoke-ShareFinder, SoftPerfect Network Scanner), pivoted to the domain controller via RDP, and extracted NTDS.dit/SYSTEM/SECURITY hives by abusing wbadmin.exe's local backup function to bypass direct file-locking. Veeam Backup & Replication credentials were harvested by querying the VeeamBackup PostgreSQL database directly via psql.exe and decrypting DPAPI-protected values with a hardcoded salt for legacy Veeam passwords. LSASS memory was dumped across three hosts using the lsassy technique (SMB, WMI, Task Scheduler, and DCOM execution methods) via rundll32.exe invoking comsvcs.dll's MiniDump export, with dump files disguised using randomized names and misleading extensions (.sys, .docx, .avhdx).
Persistence was established through new domain accounts (backup_DA, backup_EA) added to Enterprise Admins, a compromised local Administrator account, and RustDesk installed as a Windows service for remote access. A reverse SSH tunnel to 193.242.184.150 exposed internal RDP (3389) on remote port 10400, enabling RDP-over-SSH bridging and roughly 2.5GB of SYSVOL exfiltration. Approximately 39 hours after initial access, the actor began exfiltrating data via a FileZilla SFTP client (installed via FileZilla_3.68.1_win64_sponsored2-setup.exe, username "Stark") to 185.174.100.203:22, a Ukraine-hosted server on AS-COLOCROSSING, across two sessions totaling ~77GB (39.28GB and 41.77GB), including DPAPI master keys, RSA keys/certificates, Windows Credential Manager stores, browser data, cloud credentials (.aws, gcloud, Azure), password-manager vaults, source-code repositories, and mRemoteNG configs.
Approximately 44 hours after initial compromise, the actor deployed Akira ransomware (locker.exe, e.g. "locker.exe -p=G:\ -n=15") against backup and file servers on the root domain, deleting shadow copies via PowerShell/WMI (Get-WmiObject Win32_Shadowcopy | Remove-WmiObject) roughly one second after each execution. Two days later the actor returned via RustDesk, compromised a child domain controller, enumerated it with Get-ADComputer/Get-ADUser/DNS zone export, and executed Akira 39 additional times. A parallel Swisscom-affiliated incident referenced in the same report showed the actor moving from initial access to ransomware deployment in roughly nine hours, using BYOVD (rwdrv.sys/mgdsrv, hlpdrv.sys/KMHLPSVC) and AV-killer utilities (icardagt.exe, mfpmp.exe) to disable endpoint security, plus Cloudflare Tunnel (cloudflared) for covert remote access and
Weaknesses (CWE)
CWE-494, CWE-506
Target sectors: small-and-medium-business, education, critical-manufacturing, information-technology, health, financial-services, food-and-agriculture
Target regions: North America, Europe, australia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 58 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1608.006, T1583.001, T1588.002, T1189, T1204.002, T1059.001, T1059.003, T1047, T1569.002, T1543.003