{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Adversaries targeting Active Directory and Veeam credentials can cripple an organization's recovery capability before deploying ransomware. Hunting these precursors is critical for prevention."
      },
      "name": "Bumblebee Persistence and AD Credential Harvesting",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1082",
        "attack.t1016",
        "attack.t1136.002",
        "attack.t1543.003",
        "attack.t1021.001",
        "attack.t1572",
        "attack.t1003.003",
        "attack.t1003.001",
        "attack.t1552.004",
        "command and control",
        "credential access",
        "discovery",
        "execution",
        "exfiltration",
        "impact",
        "initial access",
        "lateral movement"
      ],
      "series": {
        "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
        "index": 2,
        "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
        "total": 3
      },
      "related": [
        {
          "hunt": "bumblebee-initial-access-and-sideloading",
          "reason": "This hunt focuses on the post-infection stage after Bumblebee has been deployed.",
          "relation": "precedes"
        },
        {
          "hunt": "akira-ransomware-impact-and-exfiltration",
          "reason": "Data exfiltration and encryption are the final stages after credential harvesting is complete.",
          "relation": "follows"
        },
        {
          "hunt": "bumblebee-delivery-and-c2-establishment",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "network": {
          "name": "Network telemetry",
          "category": "network",
          "telemetry": [
            "network"
          ]
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "While a rule might flag wbadmin, this hunt correlates the discovery commands, the rare SSH/RDP connection pairs, and the resulting credential harvesting events to build a high-confidence narrative of an intrusion in progress.",
      "coverage": [
        {
          "stage": "internal-discovery-and-persistence",
          "steps": [
            "discovery-and-tunneling-lead",
            "triage-intrusion-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "lateral-movement-tunneling",
          "steps": [
            "rare-network-peers",
            "triage-intrusion-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-access-harvesting",
          "steps": [
            "credential-harvesting-events",
            "script-forensics-review"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-seo-redirection",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-dll-side-loading",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-establishment-adaptix",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "data-exfiltration-sftp",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "impact-ransomware-encryption",
          "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "SEO Poisoning Redirection",
            "slug": "initial-access-seo-redirection",
            "tactic": "initial-access",
            "techniques": [
              "T1189",
              "T1583.008"
            ],
            "observables": [
              "opmanager.pro",
              "download-center.online",
              "ip-scanner.org",
              "download-server.online",
              "soft-server.online",
              "soft-hub.pro",
              "netml.shop",
              "/Get?q="
            ]
          },
          {
            "name": "Bumblebee DLL Side-Loading",
            "slug": "execution-dll-side-loading",
            "tactic": "execution",
            "techniques": [
              "T1204.002",
              "T1574.002"
            ],
            "observables": [
              "ManageEngine-OpManager.msi",
              "consent.exe",
              "msimg32.dll",
              "%TEMP%\\ApplicationInstallationFolder_11",
              "ApplicationInstallationFolder_11"
            ]
          },
          {
            "name": "AdaptixC2 Infrastructure Setup",
            "slug": "c2-establishment-adaptix",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1568.002",
              "T1055"
            ],
            "observables": [
              "AdgNsy.exe",
              "4.239.95.1:8080",
              "84.32.84.32"
            ]
          },
          {
            "name": "Internal Reconnaissance and Persistence",
            "slug": "internal-discovery-and-persistence",
            "tactic": "discovery",
            "techniques": [
              "T1082",
              "T1016",
              "T1136.002",
              "T1543.003"
            ],
            "observables": [
              "systeminfo",
              "nltest",
              "RustDesk",
              "Enterprise Admin accounts"
            ]
          },
          {
            "name": "SSH Tunneling and RDP Pivot",
            "slug": "lateral-movement-tunneling",
            "tactic": "lateral-movement",
            "techniques": [
              "T1021.001",
              "T1572"
            ],
            "observables": [
              "reverse SSH tunnel",
              "RDP proxy traffic"
            ]
          },
          {
            "name": "Active Directory and Veeam Credential Harvesting",
            "slug": "credential-access-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1003.003",
              "T1003.001",
              "T1552.004"
            ],
            "observables": [
              "wbadmin.exe",
              "ntds.dit",
              "lsassy",
              "Veeam credential dumping script"
            ]
          },
          {
            "name": "Data Exfiltration via SFTP",
            "slug": "data-exfiltration-sftp",
            "tactic": "exfiltration",
            "techniques": [
              "T1048.003",
              "T1020"
            ],
            "observables": [
              "FileZilla.exe",
              "75GB exfiltrated",
              "Ukrainian IP space"
            ]
          },
          {
            "name": "Akira Ransomware Impact",
            "slug": "impact-ransomware-encryption",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1490",
              "T1047"
            ],
            "observables": [
              "locker.exe",
              "delete Volume Shadow Copies",
              "WMI"
            ]
          }
        ],
        "summary": "Threat actors utilized Bing SEO poisoning to deliver Bumblebee malware via trojanized software installers, leading to the deployment of AdaptixC2 for network discovery. The attackers leveraged RDP over SSH tunnels to move laterally and harvest credentials from NTDS.dit and LSASS before exfiltrating 75GB of data and deploying Akira ransomware."
      },
      "severity": "high",
      "rationale": "Focus on Domain Controllers, backup servers, and the initial beachhead host. Prioritize servers running PowerShell or harboring standard IT tools in AppData folders.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "hunt-scoping",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "The suspected beachhead hosts identified in the lead step; leave empty to scan the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine for persistence and discovery."
        },
        "discovery_tools": {
          "from": {
            "ref": "dfir-report-bumblebee-akira",
            "kind": "article",
            "observed": "2026-06-29"
          },
          "type": "list[string]",
          "default": [
            "systeminfo.exe",
            "nltest.exe",
            "rustdesk.exe"
          ],
          "description": "Legitimate tools often repurposed for discovery and persistence."
        },
        "credential_tools": {
          "from": {
            "ref": "dfir-report-bumblebee-akira",
            "kind": "article",
            "observed": "2026-06-29"
          },
          "type": "list[string]",
          "default": [
            "wbadmin.exe",
            "lsassy.exe"
          ],
          "description": "Tools used to harvest credentials or dump databases."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
          "name": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira"
        }
      ],
      "blind_spots": [
        {
          "id": "no-clipboard-telemetry",
          "risk": "An adversary can move tools onto a server via clipboard without generating a file-transfer network log.",
          "stage": "lateral-movement-tunneling",
          "question": "whether FileZilla was introduced via RDP clipboard",
          "requires": "EDR clipboard audit logs"
        },
        {
          "id": "obfuscated-script-truncation",
          "risk": "Mixed-case obfuscation and script-block fragmentation can make automated detection difficult.",
          "stage": "credential-access-harvesting",
          "question": "whether custom credential-decryption scripts were used",
          "requires": "hb_script_activity with high block counts"
        }
      ]
    },
    "name": "Bumblebee Persistence and AD Credential Harvesting",
    "description": "This hunt identifies post-initial-access activities following a Bumblebee infection, specifically focusing on internal reconnaissance, persistent remote access, and high-value credential harvesting. It follows a funnel flow: starting with a lead query for common discovery tools and SSH tunneling parameters, then fanning out to stack-count rare RDP/SSH destinations and search for Active Directory database extraction artifacts. An agent triages the results to distinguish between legitimate IT maintenance and the Akira ransomware attack chain."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira",
          "index": 2,
          "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
          "total": 3
        },
        "coverage": [
          {
            "stage": "internal-discovery-and-persistence",
            "steps": [
              "discovery-and-tunneling-lead",
              "triage-intrusion-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "lateral-movement-tunneling",
            "steps": [
              "rare-network-peers",
              "triage-intrusion-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-access-harvesting",
            "steps": [
              "credential-harvesting-events",
              "script-forensics-review"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-seo-redirection",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-dll-side-loading",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-establishment-adaptix",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "data-exfiltration-sftp",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "impact-ransomware-encryption",
            "reason": "Belongs to another part of the 'From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.",
        "blind_spots": [
          {
            "id": "no-clipboard-telemetry",
            "risk": "An adversary can move tools onto a server via clipboard without generating a file-transfer network log.",
            "stage": "lateral-movement-tunneling",
            "question": "whether FileZilla was introduced via RDP clipboard",
            "requires": "EDR clipboard audit logs"
          },
          {
            "id": "obfuscated-script-truncation",
            "risk": "Mixed-case obfuscation and script-block fragmentation can make automated detection difficult.",
            "stage": "credential-access-harvesting",
            "question": "whether custom credential-decryption scripts were used",
            "requires": "hb_script_activity with high block counts"
          }
        ],
        "scoping_notes": "Focus on Domain Controllers, backup servers, and the initial beachhead host. Prioritize servers running PowerShell or harboring standard IT tools in AppData folders.",
        "beyond_detection": "While a rule might flag wbadmin, this hunt correlates the discovery commands, the rare SSH/RDP connection pairs, and the resulting credential harvesting events to build a high-confidence narrative of an intrusion in progress."
      }
    },
    {
      "id": "discovery-and-tunneling-lead",
      "type": "query",
      "label": "Discovery Tools and SSH Tunneling Lead",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{discovery_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR ((LOWER(process_name) = 'ssh.exe' OR LOWER(process_name) = 'plink.exe') AND (LOWER(process_cmd_line) LIKE '% -r %:%:%' OR LOWER(process_cmd_line) LIKE '% -l %:%:%'))) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify hosts running reconnaissance tools or showing signs of reverse SSH tunnel configurations.",
        "expected_signal": "Execution of systeminfo, nltest, or RustDesk, or an SSH client configured with reverse/local port forwarding."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Discovery Tools and SSH Tunneling Lead",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{discovery_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR ((LOWER(process_name) = 'ssh.exe' OR LOWER(process_name) = 'plink.exe') AND (LOWER(process_cmd_line) LIKE '% -r %:%:%' OR LOWER(process_cmd_line) LIKE '% -l %:%:%'))) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Execution of systeminfo, nltest, or RustDesk, or an SSH client configured with reverse/local port forwarding.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "rare-network-peers",
      "type": "query",
      "label": "Identify Rare RDP and SSH Peers",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (dst_endpoint_port = 22 OR dst_endpoint_port = 3389) AND state_kind = 'log' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC",
        "surface": "hb_network_connection",
        "description": "Stack-count network connections on ports 3389 and 22 to find rare destinations, scoped to suspected beachhead hosts.",
        "expected_signal": "An IP address receiving RDP or SSH traffic from only one or two hosts, which is atypical for centralized management gateways."
      },
      "parents": [
        {
          "id": "discovery-and-tunneling-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Identify Rare RDP and SSH Peers",
        "reads": [
          "dst_endpoint_ip",
          "dst_endpoint_port",
          "device_hostname",
          "state_kind",
          "time"
        ],
        "source": "hb_network_connection",
        "target": "network",
        "content": "SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (dst_endpoint_port = 22 OR dst_endpoint_port = 3389) AND state_kind = 'log' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING host_count <= 2 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "An IP address receiving RDP or SSH traffic from only one or two hosts, which is atypical for centralized management gateways.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "dst_endpoint_ip"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "credential-harvesting-events",
      "type": "query",
      "label": "Credential Harvesting and AD Dumping",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{credential_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%ntds.dit%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Search for direct evidence of Active Directory database dumping or LSASS memory harvesting, scoped to suspected beachhead hosts.",
        "expected_signal": "Usage of wbadmin to export the NTDS database or lsassy to dump memory, often on a Domain Controller."
      },
      "parents": [
        {
          "id": "discovery-and-tunneling-lead"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "Credential Harvesting and AD Dumping",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{credential_tools}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%ntds.dit%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Usage of wbadmin to export the NTDS database or lsassy to dump memory, often on a Domain Controller.",
        "verified": "dry-run",
        "verified_at": "2026-09-29"
      }
    },
    {
      "id": "triage-intrusion-activity",
      "type": "analytic",
      "label": "Triage Intrusion Indicators",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "network"
        ],
        "context": [
          "discovery-and-tunneling-lead",
          "rare-network-peers",
          "credential-harvesting-events"
        ],
        "objective": "Determine whether the evidence across discovery, network peers, and credential access indicates an active threat actor in the post-initial-access stage.",
        "description": "Weigh the discovery tools, rare network connections, and credential harvesting events to confirm an intrusion.",
        "max_iterations": 5,
        "expected_signal": "A per-host verdict correlating the three types of evidence.",
        "success_criteria": "Verdicts must distinguish between legitimate IT tool usage and unauthorized activity like NTDS dumping or reverse SSH tunneling."
      },
      "parents": [
        {
          "id": "rare-network-peers",
          "kind": "merge"
        },
        {
          "id": "credential-harvesting-events",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on Verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage verdict identifies malicious activity on a domain controller or backup server",
        "condition": "the triage verdict identifies malicious activity on a domain controller or backup server",
        "blind_spot": "no-clipboard-telemetry",
        "confidence": "high",
        "description": "Decide whether to isolate a host or perform manual forensic review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-intrusion-activity"
        }
      ]
    },
    {
      "id": "isolate-compromised-host",
      "type": "action",
      "label": "Isolate Compromised Host",
      "config": {
        "target": "endpoint",
        "description": "Contain the threat and prevent further lateral movement or exfiltration.",
        "instructions": "Isolate the host immediately. Revoke any Enterprise Admin group changes observed in the last 48 hours.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "script-forensics-review",
      "type": "task",
      "label": "Script Forensics Review",
      "config": {
        "assignee": "analyst",
        "description": "Manually inspect script content for custom Veeam or DPAPI credential dumping logic.",
        "instructions": "Query hb_script_activity for the host in question; look for blocks decrypting DPAPI or referencing Veeam password paths."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-compromised-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close Out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and remediation results.",
        "instructions": "Record all found accounts and hosts. Note any gaps in script telemetry where mixed-case obfuscation was observed."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "script-forensics-review"
        }
      ]
    }
  ]
}