<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul" -->

---
title: From Bing Search to Ransomware: Bumblebee and AdaptixC2...
description: A detailed forensic analysis of a multi-stage ransomware intrusion that began with SEO poisoning on Bing, luring users to a trojanized ManageEngine OpManager...
canonical: https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira | daily.dev
og:description: A detailed forensic analysis of a multi-stage ransomware intrusion that began with SEO poisoning on Bing, luring users to a trojanized ManageEngine OpManager...
og:url: https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul
og:image: https://api.daily.dev/og/posts/zXZTIjvuL.png
og:image:alt: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

**[The DFIR Report](https://daily.dev/sources/dfir-report)** · 35 min read · 0 upvotes · 0 comments

## Summary

A detailed forensic analysis of a multi-stage ransomware intrusion that began with SEO poisoning on Bing, luring users to a trojanized ManageEngine OpManager installer. The BumbleBee loader was deployed via DLL side-loading, followed by an AdaptixC2 beacon for persistent C2. Over five days, threat actors performed extensive credential harvesting (NTDS.dit, Veeam, LSASS), lateral movement via RDP and reverse SSH tunnels, and exfiltrated over 75GB of data via FileZilla/SFTP to a server in Ukraine. The intrusion concluded with Akira ransomware deployment across root and child domains, with Volume Shadow Copies deleted via WMI. A parallel Swisscom intrusion tied to the same campaign is also documented, including BYOVD attacks and Cloudflare tunnel persistence.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3>

---

Tags: [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware), [#active-directory](https://daily.dev/tags/active-directory)

[View this post on daily.dev](https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira","url":"https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul"},"datePublished":"2026-06-29T14:12:14.661Z","dateModified":"2026-06-29T14:12:44.701Z","description":"A detailed forensic analysis of a multi-stage ransomware intrusion that began with SEO poisoning on Bing, luring users to a trojanized ManageEngine OpManager...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/74df291524f6915b02a32367656d2774?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/74df291524f6915b02a32367656d2774?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The DFIR Report","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The DFIR Report","logo":"https://media.daily.dev/image/upload/s--Fa44UqJW--/f_auto,q_auto/v1780213332/logos/dfir-report?_a=BAMAMiWQ0","url":"https://daily.dev/sources/dfir-report"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-zxztijvul","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,ransomware,active-directory","timeRequired":"PT35M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The DFIR Report","item":"https://daily.dev/sources/dfir-report"},{"@type":"ListItem","position":3,"name":"From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira"}]}
```

