From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

2026-07-30T20:51:39Zbb1fb960dc8320aed52b5bdd5229a0075e371b239fb6d9e37633f67dc2caca1c
CVE-2023-46604CVE-2025-55182AdaptixC2AkiraApache-ActiveMQBissa-scannerBumblebeeC2EtherRATGentleman-ransomwareInterlock-RATLockBitLunar-SpiderLynx-ransomwareRDPRansomHubSEO-poisoningTukTukcredential-harvestinginitial-accesslateral-movementmass-exploitationpassword-sprayingransomwareremote-access-trojan

What happened

The DFIR Report RSS collection covers recent ransomware and intrusion activity, including Akira delivered through Bumblebee and AdaptixC2 after SEO poisoning, EtherRAT and TukTuk activity leading to Gentleman ransomware, AI-assisted Bissa mass exploitation and credential harvesting, Apache ActiveMQ exploitation via CVE-2023-46604 leading to LockBit, and other campaigns involving Lynx, Lunar Spider, Interlock, RansomHub, and multiple ransomware gangs. Techniques include exploitation of internet-facing services, exposed RDP access, password spraying, phishing or single-click delivery, remote tro

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
thedfirreport
Record identifier
bb1fb960dc8320aed52b5bdd5229a0075e371b239fb6d9e37633f67dc2caca1c
Enrichment time
2026-07-30T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira · Baitaphish