From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
The full DFIR Report expands on the Bumblebee-to-Akira kill chain with dual-intrusion data from Swisscom B2B CSIRT, providing deeper IOCs and lateral-movement TTPs useful for detection engineering.
Summary written by editorial AI · Source link below
Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs […] The post From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report .
Editorial Analysis
Cross-referenced data from two intrusions gives defenders richer detection signatures and lateral-movement patterns to hunt for proactively.
Ingest the expanded IOC set and TTP mappings into your SIEM and threat-hunting playbooks for Akira ransomware.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at The DFIR Report in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul