Skip to content

Executive Summary

The Swisscom incident reports an advanced cyber campaign that utilized multiple tools and techniques to infiltrate a target organization. The threat actors employed BumbleBee, AdaptixC2, and RustDesk for command-and-control (C2), lateral movement, persistence, and encryption/decrypting of sensitive data. This intrusion highlighted the use of DNS poisoning, DLL injection, file sharing, shellcode insertion, memory dumping, and encrypted exfiltration methods.
The timeline shows a continuous evolution from initial access to deployment and exfiltration phases. The BumbleBee campaign is traced back to May 2025 with its SEO poisoning strategy targeting enterprise software suites, including ManageEngine OpManager. AdaptixC2 was introduced in July 2025 during the first intrusion, followed by a resurgence using these tools on two days later.
The malware used Bumblebee variants to impersonate legitimate websites and install trojanized MSI packages that contained payloads to exfiltrate credentials and sensitive files from domain controllers.

Facts Only

In July 2025, the initial infiltration was triggered via SEO poisoning through a trojanized installer for ManageEngine OpManager, leading to an AdaptixC2 beacon being dropped.
On the second day of intrusion, the threat actor pivoted to pivot to a domain controller and dumped the NTDS.dit file to exfiltrate data. They also engaged in lateral movement using RDP sessions and dropped additional artifacts on multiple servers.
The third day saw the deployment of Akira ransomware that was staged as locker.exe via PowerShell commands, deleting Volume Shadow Copies for maximum impact.

Full Take

The BumbleBee campaign is a sophisticated example of how attackers leverage multiple tools to maintain persistence, escalate privileges, and exfiltrate data within corporate environments. The AdaptixC2 agent establishes command-and-control channels over DGA domains, facilitating lateral movement through the use of reverse SSH tunnels.

From the original · The DFIR Report

Key Takeaways - In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager. - Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit. - The threat actor returned the following day and established an SSH…
Read the full story at thedfirreport.com

Sentinel — Synthetic

Confidence

This article is likely written by a human journalist due to its structured narrative structure, multiple coordination indicators, and lack of AI-generated language characteristics.

Signals Detected
low severity: The text exhibits an elaborate structure with multiple coordination indicators, including the consistent use of 'and' and repetition of phrases that suggest a structured narrative.
Human Indicators
Analysts completed in-depth forensic analysis using various techniques such as Sysmon logs, PowerShell scripts, and network traffic inspection to confirm the findings.
The text does not contain any evidence of AI or automated writing patterns beyond typical human editing practices.
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira | Huntaegis