ctipilot.ch

Bumblebee → AdaptixC2 → Akira: SEO-poisoning-to-ransomware kill chain (DFIR Report; Swisscom CSIRT parallel intrusion)

incident · item:dfir-bumblebee-adaptixc2-akira-seo-poisoning-killchain

Coverage timeline
1
first 2026-06-30 → last 2026-06-30
Briefs
1
1 distinct
Sources cited
3
2 hosts
Sections touched
1
deep_dive
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-06-30CTI Daily Brief — 2026-06-30
    deep_diveDeep dive. Full kill chain: poisoned Bing→trojanized OpManager MSI→Bumblebee DLL-sideload→AdaptixC2→EA accounts via RSAT→NTDS.dit/Veeam→77GB SFTP exfil→Akira via WMI. Swisscom B2B CSIRT observed second intrusion same campaign.

Where this entity is cited

  • deep_dive1

Source distribution

  • attack.mitre.org2 (67%)
  • thedfirreport.com1 (33%)

Items in briefs about Bumblebee → AdaptixC2 → Akira: SEO-poisoning-to-ransomware kill chain (DFIR Report; Swisscom CSIRT parallel intrusion)

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.