An IT administrator searched Bing for "ManageEngine OpManager", clicked a paid-looking result, and installed what appeared to be network monitoring software. Forty-four hours later the domain was encrypted by Akira, 77 GB was already on a server in Ukraine, and the attacker still had a RustDesk service installed for the return visit.
The whole intrusion is documented by The DFIR Report in From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira (29 June 2026). This article is analysis of their data, not original research - every figure, command and indicator below is theirs, and the report is worth reading in full.
What makes it worth writing about is that almost nothing in the chain was exotic. The initial access was a search engine advert. The persistence was a commercial remote-desktop tool. The credential theft used a Microsoft backup utility exactly as designed. The most interesting technical content is not the malware; it is how much of the operation ran on software the defenders had already approved.
thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/. Intrusion occurred July 2025. All indicators reproduced here are from that report.//Access Was Bought, Not Found
No vulnerability was exploited to get in. The operators poisoned Bing results for a legitimate product and waited for an administrator to come to them.
The redirect chain ran opmanager[.]pro to download-center[.]online, delivering ManageEngine-OpManager.msi. The installer carried a genuine Authenticode signature from "LLC Resource+" - revoked by the time of reporting, but valid enough at execution to clear the bar most users and some tooling apply.
The MSI then did something worth pausing on: it installed the real software. ManageEngine_OpManager_64bit.exe was dropped alongside the payload into %TEMP%\ApplicationInstallationFolder_11. The administrator got the tool they searched for, working as expected. There was no failed install to investigate, no error to report to a helpdesk.
Note also who ran it. The victim was an IT administrator installing network monitoring software - someone with the privileges to do damage and the professional context to be installing exactly this kind of tool. That is not accidental targeting. Choosing "ManageEngine OpManager", "Advanced IP Scanner" and "MIB Browser" as the poisoned search terms selects for administrators the way a phishing lure selects for finance staff.
The side-load
Two other files landed in that directory: consent.exe, the legitimate Windows UAC consent binary, and msimg32.dll, which was Bumblebee.
Windows resolves a DLL by searching the application's own directory before System32. Copy a signed Microsoft binary into a folder you control, put a malicious DLL with the right name beside it, and the operating system loads your code into a trusted process for you. The technique is old and the defence is well understood, and it keeps working because the executable really is Microsoft's, really is signed, and really is doing what it was built to do.
Bumblebee's own tradecraft is more interesting than the loading trick. Before doing anything it called GetSystemDefaultLocaleName() and compared the result against 27 CIS-region locales, exiting silently on a match. That is the familiar don't-burn-the-neighbourhood check, and it doubles as a sandbox evasion. Its DGA produced 14-character .org domains in this wave. Its PE metadata strings were dictionary-derived gibberish - not random bytes, which look wrong, but plausible-looking words in implausible combinations, which is a strong YARA target precisely because it is a generator artefact rather than a deliberate choice.
//Five Hours of Nothing, Then a Human
Bumblebee beaconed for about five hours before anything else happened. That gap is the handoff - loader access sold or passed to an operator who then logged in and started typing.
What arrived was AdgNsy.exe, a renamed copy of the Windows Address Book utility, carrying injected AdaptixC2 shellcode and executing under WmiPrvSE.exe. Discovery was entirely living-off-the-land:
systeminfonltest /dclist:whoami /groupsnet group domain admins /dom
Four commands, all built in, all run legitimately by administrators every day. In isolation each is noise. Run within ninety seconds of each other by a process called AdgNsy.exe living in a temp directory, they are an intrusion.
Persistence that looks like IT
The operator created two domain accounts named to survive a casual audit:
net user backup_DA P@ssw0rd1234 /add /domnet user backup_EA P@ssw0rd1234 /add /domnet group "enterprise admins" backup_EA /add /dom
backup_DA and backup_EA read as service accounts for a backup product. An administrator scanning a user list at speed sees plumbing, not an attacker. The password is trivially weak, which tells you the accounts were never expected to survive scrutiny - they only needed to last two days.
Then RustDesk was installed as a Windows service across multiple servers. Commercial, signed, legitimately used by managed service providers, and almost never on an EDR blocklist by default. The return visit on day five came through it.
//Credential Access Without the Tools Anyone Watches
This is the part worth studying. Most detection content around ntds.dit theft focuses on ntdsutil, vssadmin, or a raw volume shadow copy service call. The operator used none of them.
wbadmin.exe start backup -backuptarget:\\127.0.0.1\C$\ProgramData\ -include:C:\windows\NTDS\ntds.dit
Windows Server Backup. A Microsoft-signed administrative utility, present by default on domain controllers, whose entire purpose is to copy files that are locked and in use. Pointing it at the Active Directory database is not an abuse of a bug - it is the tool performing its function, against a target chosen by the operator. Note the backup target is a UNC path to the local machine's own admin share, which keeps the whole operation on one host.
Two more credential sources followed. Veeam backup credentials were pulled straight out of PostgreSQL:
psql.exe -U postgres --csv -d VeeamBackup -w -c "SELECT user_name,password..."
And lsassy was run against LSASS, cycling through four remote execution methods - SMB, WMI, scheduled tasks and DCOM - with randomised output filenames staged in \Windows\Temp, including deliberately incongruous extensions such as G7wO.sys and U8Vfsh.docx. A .docx in Windows\Temp containing an LSASS dump is a good reminder that file extensions are a naming convention, not a fact.
Backup infrastructure was the recurring theme: the backup database for credentials, the backup utility for the AD database, backup-themed account names. Backup systems hold credentials to everything and are frequently excluded from the monitoring applied to production.
//Exfiltration, Then Encryption
FileZilla was brought in over the RDP clipboard - a transfer channel that leaves no download in a proxy log - and written to C:\ProgramData\FileZilla_3.68.1_win64_sponsored2-setup.exe. Roughly 77 GB left over SFTP to 185[.]174[.]100[.]203:22 under the username Stark, in two sessions of about 39 GB and 42 GB, each running around four and a half hours.
Nine hours of sustained outbound SFTP to a single foreign IP is, in retrospect, the loudest thing in this entire intrusion. It is also the stage with the least sophistication: a standard FTP client, default port, no tunnelling.
Akira ran at about the 44-hour mark from C:\ProgramData\locker.exe:
locker.exe -p=G:\ -n=15
The -n=15 flag sets partial encryption - 15% of each file. Enough to destroy the data, fast enough to finish before anyone can intervene. Shadow copies went via WMI rather than vssadmin:
powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"
On day five they came back through RustDesk, pivoted to a child domain controller, and ran the binary 39 times.
//What the Infrastructure Says
The DFIR Report tracked two waves, and the comparison is the most informative part of the writeup.
May 2025: WinMTR, Zenmap, RVTools, Milestone XProtect. Staging on download-server[.]online and soft-server[.]online. Side-load chain icardagt.exe to version.dll. 13-character .lifeDGA domains. Certificates from "LLC Ellada Comfort" and "LLC Vector".
July 2025: ManageEngine OpManager, Advanced IP Scanner, MIB Browser. Staging on download-center[.]online and soft-hub[.]pro. Side-load chain consent.exe to msimg32.dll. 14-character .orgDGA domains. Certificates from "LLC Resource+", "LLC Ugurmana", "LLC Leighton" and "LLC Vector".
Everything visible rotated - the lure software, the domains, the side-load pair, the DGA shape, most of the signers. Two things did not: the hosting, all resolving to Hostinger AS47583, and the "LLC Vector" certificate appearing in both waves.
That is the shape of a capability with a supplier. Shell companies are being registered and burned for code-signing certificates at a rate that suggests a pipeline rather than one-off purchases, yet one signer leaks across both waves, and the hosting never moves.
The Ivanti campaign is the more interesting footnote
In October 2025 a separate operation poisoned Bing results for Ivanti VPN software. The DFIR Report describes a nearly identical tactical fingerprint: the same two-tier SEO structure, the same /Get?q= URL parameter, staging on the same Hostinger IP (84.32.84.32) that hosted Wave 1's soft-server[.]online.
But the payload was a dedicated credential stealer rather than Bumblebee, the signer was Chinese ("Hefei Qiangwei Network Technology"), and it beaconed to a hardcoded Azure address instead of DGA domains.
Same delivery machinery, different customer. The most parsimonious reading is that the SEO poisoning and staging are a service being sold to multiple actors, with each bringing their own payload and signing arrangements. That has a practical consequence: the delivery fingerprint is a hunting opportunity across unrelated campaigns, but it is not attribution. Two intrusions sharing that /Get?q= pattern may have nothing else in common.
The report presents this as a possibility rather than a conclusion, and it is worth keeping it that way.
//Detection Opportunities
The DFIR Report publishes Sigma rules and YARA signatures; what follows is a reading of where this chain was most visible, not a substitute for those.
System binaries outside their system path. consent.exe executing from %TEMP% is anomalous on any Windows host, requires no threat intelligence to spot, and sits at the very start of the chain. Same for icardagt.exe in the earlier wave. This is the single highest-value signal here.
wbadmin targeting ntds.dit. Legitimate backups of a domain controller do not name the AD database explicitly on the command line. Detection content built around ntdsutil and vssadmin misses this entirely.
Account creation with backup-themed names followed by group changes. The pairing of net user /add /dom and net group "enterprise admins" /add within minutes is the event; either alone is ordinary.
psql.exe querying the VeeamBackup database from anything other than Veeam itself.
Sustained high-volume outbound SFTP. Two multi-hour sessions moving 39 GB and 42 GB to one external IP. Volumetric egress alerting is unglamorous and would have caught this before the ransomware ran.
RMM tooling installed as a service where the organisation does not use it. RustDesk is legitimate, which is exactly why it needs an allowlist rather than a blocklist.
ManageEngine-OpManager.msi SHA256 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5damsimg32.dll (Bumblebee) SHA256 a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331locker.exe (Akira) SHA256 de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19dDelivery:
opmanager[.]pro, download-center[.]online, soft-hub[.]pro, download-server[.]online, soft-server[.]onlineBumblebee C2:
188.40.187[.]145, 109.205.195[.]211, 171.22.183[.]43, 192.121.22[.]94, 194.127.178[.]21AdaptixC2:
172.96.137[.]160Reverse SSH:
193.242.184[.]150 · Exfil: 185.174.100[.]203 (AS-COLOCROSSING)Signers: LLC Resource+, LLC Vector, LLC Ellada Comfort, LLC Ugurmana, LLC Leighton
Hosting: Hostinger AS47583 · Ivanti-campaign stager
84.32.84.32//Sourcing
Everything factual here comes from The DFIR Report's 29 June 2026 writeup, which maps 47 MITRE ATT&CK techniques and publishes Sigma rules and YARA signatures including BumblebeeC2, AdaptixC2_listener_beacon_http and DITEKSHEN_MALWARE_Win_Akira. Their rule IDs and full indicator set are in the original.
The interpretation is mine: the reading of backup infrastructure as the recurring target, the argument that the delivery chain is a service with multiple customers, and the ranking of detection opportunities. Where the report presents something as possible rather than established - the Ivanti campaign relationship in particular - it is presented that way here too.
One gap worth stating: the certificate history for these signers is cited by the report to certgraveyard.org, which this article has not independently verified.