A fake download page for a trusted admin tool can hand an attacker the keys to the whole domain. Once the installer runs, the problem is no longer a single compromised workstation; it becomes identity theft, persistence, and ransomware across Active Directory.
In this case, SEO poisoning led a user searching for ManageEngine OpManager to a look-alike site that served a trojanized MSI installer. The intrusion then used BumbleBee and AdaptixC2 to reach a domain controller, dump NTDS.dit, create privileged accounts, proxy traffic over SSH, steal backup credentials, move across root and child domains, and finish with Akira encryption.
Any environment that lets staff find admin software by web search is exposed to the same trust break. Patching the endpoint does not undo stolen domain credentials or stop a second-stage ransomware push into other domains.
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira - The DFIR Report
Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs […