From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
2026-06-29T20:51:52Z•75de17309a8c8bc6e631bd00b25ba3e94aa9f541cef232ea96dd4e732377204c
CVE-2023-46604CVE-2025-55182SEO poisoningadaptixc2ai-assisted exploitationakiraapache activemqbissa scannerbumblebeecredential harvestingetherratexposed serversgentleman ransomwareinitial accessinterlock ratkongtukelockbitmass exploitationpassword sprayphp malwareransomhubransomwarerdpreact2shelltuktuk
What happened
The DFIR Report feed aggregates multiple incident write-ups (2024–2026) describing active ransomware and intrusion campaigns: Bumblebee (SEO poisoning) delivering Akira via AdaptixC2; EtherRAT and TukTuk C2 activity culminating in The Gentleman ransomware (Windows and Linux variants, with prior exploitation of CVE-2025-55182/React2Shell noted); an exposed AI-assisted Bissa scanner used for large-scale mass exploitation and credential harvesting (operator tooling included Claude Code/OpenClaw); an Apache ActiveMQ RCE chain exploiting CVE-2023-46604 that led to LockBit; a new PHP-based Interlock
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- thedfirreport
- Record identifier
- 75de17309a8c8bc6e631bd00b25ba3e94aa9f541cef232ea96dd4e732377204c
- Enrichment time
- 2026-06-29T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.