A detailed threat report covering a July 2025 intrusion chain that began with SEO poisoning on Bing, directing users searching for ManageEngine OpManager to a malicious site delivering a trojanized MSI installer. The installer loaded Bumblebee malware, which then deployed an AdaptixC2 beacon for command and control. Within 44 hours, the threat actor moved laterally to a domain controller, dumped NTDS.dit credentials, created privileged backdoor accounts, installed RustDesk for persistence, exfiltrated data via FileZilla/SFTP, and deployed Akira ransomware across the root domain. Two days later, the attacker returned via RustDesk to encrypt a child domain as well. The report includes detailed detection engineering guidance covering initial access, credential access, discovery, lateral movement, exfiltration, and C2 patterns, along with full IOCs including malicious domains, C2 IPs, and file hashes.