Threat actors used SEO poisoning to steer victims searching for IT management software to lookalike sites hosting a trojanized ManageEngine OpManager installer, which delivered Bumblebee malware and opened the door to a broader intrusion that culminated in Akira ransomware. Investigators said the attackers used DLL side-loading to launch Bumblebee, then deployed an AdaptixC2 beacon by injecting it into a renamed Windows Address Book binary, linking the activity to a wider campaign also observed by Swisscom involving trojanized IT tool installers such as OpManager and IP scanner software.
After gaining access, the attackers quickly escalated privileges, created domain accounts, moved laterally with RDP and SSH-based tunneling, and stole credentials from Active Directory, LSASS, and Veeam, including dumping NTDS.dit. They established persistence with RustDesk and a reverse SSH tunnel, exfiltrated about 77 GB of data with FileZilla over SFTP and additional SYSVOL data over SSH, then deployed Akira across the root domain roughly 44 hours after compromise before returning to encrypt a child domain; in a related Swisscom case, ransomware was reached in as little as nine hours.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-30, Gurucul published a write-up on the campaign that included domains, IP addresses, and file hashes as indicators of compromise associated with the intrusion chain.
On 2026-06-29, The DFIR Report published an expanded report with additional technical details on the intrusion, including exfiltration volume, persistence methods, and correlation to parallel activity observed by Swisscom.
The reporting linked the primary intrusion to similar July 2025 incidents observed by Swisscom B2B CSIRT involving trojanized IT tool installers and comparable BumbleBee-to-ransomware tradecraft, indicating a broader campaign.
Two days after the root-domain ransomware deployment, the attackers returned and encrypted systems in a child domain as well.
About 44 hours after the initial compromise in July 2025, the attackers deployed Akira ransomware across the victim's root domain.
During the same July 2025 intrusion, the attackers exfiltrated roughly 77 GB of data using FileZilla over SFTP to a server in Ukraine and also transferred SYSVOL data over SSH.
After initial access in the July 2025 intrusion, the attackers used DLL side-loading to launch BumbleBee, deployed an AdaptixC2 beacon, created privileged domain accounts, and moved laterally while harvesting credentials from Active Directory, Veeam, and LSASS.
In July 2025, threat actors used SEO poisoning around IT management software searches to lure victims to lookalike infrastructure hosting a trojanized ManageEngine OpManager installer, which delivered BumbleBee malware for initial access.
On 2025-08-05, The DFIR Report published a flash alert describing the July 2025 intrusion chain from SEO poisoning and BumbleBee delivery to AdaptixC2 activity and Akira ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcethedfirreport.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.