Security researchers have uncovered a ransomware campaign in which attackers used search engine optimization (SEO) poisoning to distribute malware through a fake download page for ManageEngine OpManager. By manipulating search results, threat actors directed users to a fraudulent website that closely resembled the legitimate software download page. Victims who downloaded and executed the malicious installer unknowingly launched a multi-stage attack that ultimately resulted in the deployment of Akira ransomware. The malicious installer delivered BumbleBee malware, which established an initial foothold and later deployed an AdaptixC2 beacon to maintain persistent remote access. Over the next two days, the attackers conducted reconnaissance, created unauthorized administrator accounts, installed remote access software, harvested credentials, extracted the Active Directory database, and exfiltrated more than 75 GB of sensitive data. The attackers then deployed Akira ransomware across the network, deleted Volume Shadow Copies to prevent recovery, and encrypted systems, causing significant operational disruption. This campaign demonstrates how trusted search results can be abused to compromise enterprise environments, particularly when IT administrators download software from unofficial sources. Organizations should verify software downloads through official vendor websites, restrict execution of untrusted MSI files, monitor for unauthorized administrator account creation, and detect unexpected installation of remote access tools. Continuous endpoint monitoring, timely patch management, and user awareness training are essential to reduce the risk of similar attacks and limit the impact of ransomware intrusions.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...