A user downloaded a trojanized MSI from an SEO-poisoned site, which used DLL sideloading to establish C2 and persistence through new admin accounts. The threat actor then moved laterally with RDP/SSH tunneling, harvested credentials via wbadmin and custom scripts, exfiltrated over 75GB of data, and deployed Akira ransomware.
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
This case highlights a multi-stage campaign from initial SEO lure to credential theft and ransomware deployment — useful for building detections across the full kill chain (sideloading, persistence, lateral movement).
Read the original at The DFIR Report →
Subscribe
Short, high-signal articles and news summarized — at a frequency of your choosing. One click to subscribe.