Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bing Search Leads to Akira Ransomware Attack via SEO Poisoning

Bing Search Leads to Akira Ransomware Attack via SEO Poisoning

Posted on June 30, 2026 By CWS

A recent Bing search for a well-known IT management tool has resulted in a widespread ransomware attack, leveraging SEO poisoning techniques. Cybercriminals manipulated search engine results to redirect users to a malicious download, masquerading as legitimate software, thereby compromising IT administrators’ systems.

SEO Manipulation and Initial Attack

The attack was initiated in July 2025 when a Bing search for ‘ManageEngine OpManager’ redirected users to a fake domain mimicking the official software site. This deceptive page offered a trojanized MSI installer, leading to a sophisticated multi-day cyber intrusion, culminating in the deployment of Akira ransomware across the victim’s network.

According to a joint report by The DFIR Report and Swisscom B2B CSIRT, the attackers employed BumbleBee malware and an AdaptixC2 beacon to gain and maintain unauthorized access. This strategic assault involved creating false admin accounts and installing remote access software to exfiltrate over 75GB of sensitive data to a server located in Ukraine.

Technical Details and Execution

The attack was meticulously executed over approximately 44 hours. Initially, the attackers used Windows Management Instrumentation to erase Volume Shadow Copies before encrypting the systems with Akira ransomware, disguised as locker.exe. Two days later, they targeted a child domain, ensuring complete network disruption.

The compromised download originated from opmanager[.]pro, a domain placed prominently in Bing search results through SEO poisoning. This site replicated the genuine ManageEngine download page, ultimately redirecting users to download malicious software from download-center[.]online.

Advanced Techniques and Persistence

Within five hours of infection, BumbleBee deployed AdgNsy.exe, an altered version of a legitimate Windows utility injected with AdaptixC2 shellcode. This enabled a persistent command-and-control channel, facilitating network mapping and identification of crucial assets like domain controllers.

Rogue accounts named backup_DA and backup_EA were created, with the latter gaining full administrative privileges. The attackers also utilized RustDesk remote access software as a Windows service across multiple servers to ensure continued access.

On the second day, further escalation involved accessing a domain controller, extracting the Active Directory database, and siphoning off Veeam credentials. The attackers bypassed firewall protections using a reverse SSH tunnel for RDP traffic.

Preventive Measures and Recommendations

Organizations must vigilantly monitor search results for impersonations of enterprise software, particularly tools used by IT teams. Implementing strict controls on MSI execution from untrusted sources, regulating DLL load orders, and setting alerts for unexpected domain admin account creations are critical defense strategies.

Detection of unauthorized remote access tools, such as RustDesk, is vital, as these were instrumental in maintaining the attackers’ persistence throughout the incident. Strengthening security operations centers (SOCs) by integrating advanced threat detection tools is essential to mitigate such sophisticated attacks.

Cyber Security News Tags:AdaptixC2, Akira malware, Bing, BumbleBee malware, Cybersecurity, IT tools, ManageEngine OpManager, network security, Ransomware, SEO poisoning

Post navigation

Previous Post: Chris Thompson’s Journey: From Game Hacker to Cybersecurity Pioneer
Next Post: Cyber Threats Surrounding FIFA 2026: Key Insights

Related Posts

DHS Confirms HSIN Data Breach by Hackers DHS Confirms HSIN Data Breach by Hackers Cyber Security News
Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials Cyber Security News
CISOs Guide to Regulatory Compliance in Global Landscapes CISOs Guide to Regulatory Compliance in Global Landscapes Cyber Security News
ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users Cyber Security News
Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums Cyber Security News
Hackers Weaponizing SVG Files With Malicious Embedded JavaScript to Execute Malware on Windows Systems Hackers Weaponizing SVG Files With Malicious Embedded JavaScript to Execute Malware on Windows Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Citrix NetScaler Vulnerability Allows Remote Root Access
  • VINclarity Faces Coordinated Online Reputation Assault
  • SentinelOne Vulnerability Exposes EDR to Malware Risks
  • Critical TP-Link Vulnerabilities Enable Unauthorized Access
  • Crypter Services Bypass Windows Security Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Citrix NetScaler Vulnerability Allows Remote Root Access
  • VINclarity Faces Coordinated Online Reputation Assault
  • SentinelOne Vulnerability Exposes EDR to Malware Risks
  • Critical TP-Link Vulnerabilities Enable Unauthorized Access
  • Crypter Services Bypass Windows Security Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark