A user downloaded a trojanized MSI from an SEO-poisoned site, which used DLL sideloading to establish C2 and persistence through new admin accounts. The threat actor then moved laterally with RDP/SSH tunneling, harvested credentials via wbadmin and custom scripts, exfiltrated over 75GB of data, and deployed Akira ransomware.