Executive Summary
The Swisscom incident reports an advanced cyber campaign that utilized multiple tools and techniques to infiltrate a target organization. The threat actors employed BumbleBee, AdaptixC2, and RustDesk for command-and-control (C2), lateral movement, persistence, and encryption/decrypting of sensitive data. This intrusion highlighted the use of DNS poisoning, DLL injection, file sharing, shellcode insertion, memory dumping, and encrypted exfiltration methods.
The timeline shows a continuous evolution from initial access to deployment and exfiltration phases. The BumbleBee campaign is traced back to May 2025 with its SEO poisoning strategy targeting enterprise software suites, including ManageEngine OpManager. AdaptixC2 was introduced in July 2025 during the first intrusion, followed by a resurgence using these tools on two days later.
The malware used Bumblebee variants to impersonate legitimate websites and install trojanized MSI packages that contained payloads to exfiltrate credentials and sensitive files from domain controllers.
Facts Only
In July 2025, the initial infiltration was triggered via SEO poisoning through a trojanized installer for ManageEngine OpManager, leading to an AdaptixC2 beacon being dropped.
On the second day of intrusion, the threat actor pivoted to pivot to a domain controller and dumped the NTDS.dit file to exfiltrate data. They also engaged in lateral movement using RDP sessions and dropped additional artifacts on multiple servers.
The third day saw the deployment of Akira ransomware that was staged as locker.exe via PowerShell commands, deleting Volume Shadow Copies for maximum impact.
Full Take
From the original · The DFIR Report
Key Takeaways - In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager. - Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit. - The threat actor returned the following day and established an SSH…Read the full story at thedfirreport.com
Sentinel — Synthetic
This article is likely written by a human journalist due to its structured narrative structure, multiple coordination indicators, and lack of AI-generated language characteristics.
