From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
2026-07-30T20:51:39Z•bb1fb960dc8320aed52b5bdd5229a0075e371b239fb6d9e37633f67dc2caca1c
CVE-2023-46604CVE-2025-55182AdaptixC2AkiraApache-ActiveMQBissa-scannerBumblebeeC2EtherRATGentleman-ransomwareInterlock-RATLockBitLunar-SpiderLynx-ransomwareRDPRansomHubSEO-poisoningTukTukcredential-harvestinginitial-accesslateral-movementmass-exploitationpassword-sprayingransomwareremote-access-trojan
What happened
The DFIR Report RSS collection covers recent ransomware and intrusion activity, including Akira delivered through Bumblebee and AdaptixC2 after SEO poisoning, EtherRAT and TukTuk activity leading to Gentleman ransomware, AI-assisted Bissa mass exploitation and credential harvesting, Apache ActiveMQ exploitation via CVE-2023-46604 leading to LockBit, and other campaigns involving Lynx, Lunar Spider, Interlock, RansomHub, and multiple ransomware gangs. Techniques include exploitation of internet-facing services, exposed RDP access, password spraying, phishing or single-click delivery, remote tro
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- thedfirreport
- Record identifier
- bb1fb960dc8320aed52b5bdd5229a0075e371b239fb6d9e37633f67dc2caca1c
- Enrichment time
- 2026-07-30T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.