Admin Tool Search Leads to Domain-Wide Ransomware

A fake download page for a trusted admin tool can hand an attacker the keys to the whole domain. Once the installer runs, the problem is no longer a single compromised workstation; it becomes identity theft, persistence, and ransomware across Active Directory. In this case, SEO poisoning led a user searching for ManageEngine OpManager to a look-alike site that served a trojanized MSI installer. The intrusion then used BumbleBee and AdaptixC2 to reach a domain controller, dump NTDS.dit, create privileged accounts, proxy traffic over SSH, steal backup credentials, move across root and child domains, and finish with Akira encryption. Any environment that lets staff find admin software by web search is exposed to the same trust break. Patching the endpoint does not undo stolen domain credentials or stop a second-stage ransomware push into other domains.

Part of the PlainSec briefing for 2026-06-30

Sources