A seemingly innocent Bing search turned into a ransomware attack by the Akira gang , highlighting how dangerous cybercriminals’ modern deception techniques have become. The attackers exploited SEO Poisoning , the manipulation of search results, to display a fake website that mimicked the official download interface for the popular network management tool, ManageEngine OpManager .

The incident is a prime example of how even experienced IT administrators can be swayed by a particularly convincing search result, ultimately leading to a devastating breach of a corporate network.
The attack started from Bing
According to a technical analysis published by DFIR Report in collaboration with Swisscom B2B CSIRT, the attack began in July 2025 when an IT administrator searched on Bing for the popular ManageEngine OpManager, which is widely used to monitor and manage corporate networks.
See also: Blackfield: Demands $2 million from Nidec after ransomware attack
Instead of being taken to the official website of the application, the user clicked on a deceptive link that appeared very high in the search results. The website was designed to look almost exactly like the legitimate software download page, making it extremely difficult to recognize the scam.
From there, the victim was led to a second domain, where he downloaded a malicious MSI-type installation, which hid a highly sophisticated infection mechanism.
BumbleBee paved the way for attackers
Upon executing the installer, the system was infected with the notorious BumbleBee, a tool often used as the first stage of complex ransomware attacks. The installer placed the real ManageEngine OpManager program on the computer as bait, as well as additional files that allowed the malware to execute silently via the DLL Search Order Hijacking technique.

In this way, the malicious code was executed through legitimate Windows processes, significantly reducing the chances of detection by traditional protection tools.
It is noteworthy that the installation file was digitally signed with a certificate issued to a company that has been linked to BumbleBee distribution campaigns in the past.
AdaptixC2 and full control of the corporate network
Approximately five hours after the initial infection, the attackers installed AdaptixC2, an advanced Command and Control platform that allowed them to maintain permanent access to information systems.
See also: CISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability
From that point, the systematic mapping of the corporate network. The perpetrators located the Domain Controllers, created two new administrator accounts with high privileges , and gained full control of Active Directory.
At the same time, they installed the remote access software RustDesk as a Windows service on multiple servers, ensuring an alternative way to connect even if one of the original access mechanisms was detected.
They then database NTDS.dit, obtained Veeam Backup credentials , and extracted data from the LSASS process memory, gaining valuable information about the organization's accounts.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Over 75 GB of data stolen
Researchers estimate that the attackers extracted more than 75 gigabytes of sensitive data, which was transferred to a remote server hosted in Ukraine.
To avoid detection, the team used a reverse SSH tunnel, bypassing firewall restrictions and hiding the true path of communication.
From the initial infection to the completion of the preparation for the ransomware attack, approximately 44 hours elapsed, which indicates the high degree of organization of the perpetrators.
Akira ransomware completed the attack
After gaining full access to the victim's environment and completing the data theft, the attackers activated the Akira.
See also: Ransomware 2026: 49% don't understand the attack before data is stolen

The malware ran as locker.exe and used Windows Management Instrumentation (WMI) to first delete Volume Shadow Copies, thus removing one of the most basic file recovery capabilities.
The organization's systems were then encrypted. Two days later, the attackers returned and encrypted an additional child domain, further expanding the impact of the attack.
SEO Poisoning is becoming increasingly dangerous
This case demonstrates that cybercriminals are no longer limited to phishing emails or malicious attachments. Manipulation of search results is becoming one of the most effective initial access techniques, especially when targeting IT professionals searching for everyday system administration.
Experts recommend that organizations always verify the address of websites before downloading any software, restrict the execution of MSI files where possible, monitor the installation of remote access tools such as RustDesk, and implement mechanisms to detect suspicious activity on corporate networks. In an era where even a simple search can be the beginning of a major cyberattack, vigilance and the right security policy are the most effective defense.
