#adaptixc2
「Operation Master」、GlobalProtectのCVE-2026-0257を悪用し企業ネットワークにAdaptixC2を展開

「Operation Master」は、GlobalProtect VPNの悪用、Webアプリケーション攻撃、認証情報の窃取、データの収益化、そして大規模な請求書詐欺プラットフォームを組み合わせた、一貫したサイバー犯罪作戦です。 このキャンペーンは、企業への侵入がデータ窃取やランサムウェアで終わらず、現地の状況に合わ
「Operation Master」、GlobalProtectのCVE-2026-0257を悪用し企業ネットワークにAdaptixC2を展開
「Operation Master」は、GlobalProtect VPNの悪用、Webアプリケーション攻撃、認証情報の窃取、データの収益化、そして大規模な請求書詐欺プラットフォームを組み合わせた、一貫したサイバー犯罪作戦です。 このキャンペーンは、企業への侵入がデータ窃取やランサムウェアで終わらず、現地の状況に合わ
blackhatnews.tokyo
September 29, 2026 at 4:17 AM
~Malpedia~
Actor chained VPN exploits, data theft and AdaptixC2 to industrialize PIX invoice fraud.
-
IOCs: yzs[.]fi, 91[.]92[.]241[.]187, pix-proxy-sable[.]vercel[.]app
-
#Malware #Phishing #ThreatIntel
Operation Master
malpedia.caad.fkie.fraunhofer.de
September 25, 2026 at 4:08 PM
@talosintelligence.com
The Gentlemen led Japan’s 2026 ransomware activity; Qilin showed likely AI-assisted tooling.
-
IOCs: CVE-2025-24799, AdaptixC2, deadman[.]py
-
#Qilin #Ransomware #TheGentlemen #ThreatIntel
Japan Ransomware Surge
blog.talosintelligence.com
September 17, 2026 at 12:37 PM
Node.js's own signed interpreter is being weaponized to run malware past your EDR's radar. https://intel.threadlinqs.com/threat/TL-2026-2304 #ThreatIntel #KongTuke #AdaptixC2 #Cobalt
September 3, 2026 at 11:20 AM
A signed AV updater got hijacked to side-load Beagle behind a fake Claude site. https://intel.threadlinqs.com/threat/TL-2026-2120 #ThreatIntel #AdaptixC2 #Lumma #Fake
August 23, 2026 at 6:49 AM
https://
blog.deception.pro/blog/clickfix-
spacex1337-hok-2026
…

* "AsyncRAT (via a signed GoTo Meeting DLL side-load)"
* "AdaptixC2 beacon compiled on-host with csc.exe"
* "pulled from 85[.]155[.]186[.…

🔁 RT @_josehelps | reposted by @cyb3rops
https://x.com/_josehelps/status/2087606400826700126
blog.deception.pro
blog.deception.pro
t.co
August 13, 2026 at 6:40 AM
A classic case of dual-use tools being weaponized. Defenders, ensure your EDR is tuned for AdaptixC2 signatures and monitor for unusual outbound traffic. Stay sharp! 🛡️
August 8, 2026 at 8:03 AM
Open-Source Tool Turns Into Ransomware Freight Train, Surprise Absolutely Nobody
PANIC 58% | Lag 20.43h | AdaptixC2 is being reported as abused by ransomware operators to support intrusion and post-compromi
#AfterShockIndex
READ MORE
August 6, 2026 at 1:56 AM
AdaptixC2 & Domain Trusts: Chained Compromise of a Multi-Forest Active Directory Environment https://medium.com/@Xotourliff/adaptixc2-domain-trusts-chained-compromise-of-a-multi-forest-active-directory-environment-8e9f9dfa2ff7
July 24, 2026 at 9:42 AM
Open-Source C2 Turns Ransomware Into a Hobby Project With Corporate Victims
PANIC 64% | Lag 0.0h | AdaptixC2 is being reported as an open-source command-and-control tool abused in ransomware operatio
#AfterShockIndex
READ MORE
July 23, 2026 at 2:02 AM
CTA Member VMRay details their June detection highlights: AdaptixC2 Config Extractor, 5 new VTIs, and 30+ New YARA Rules
www.vmray.com/june-2026-de...
#cybersecurity
VMRay Detection & Intelligence Highlights - June 2026
Detecting discovery of the configured DNS domain, email sender spoofing, ad-click subdomains, PayPal branding ,and more.
www.vmray.com
July 17, 2026 at 6:43 PM
Open-Source Tool Turns Into Ransomware Fertilizer, Shockingly, Nobody Read the Room
PANIC 62% | Lag 10.06h | AdaptixC2 is being reported as an open-source security tool abused in ransomware operations. GrayZon
#AfterShockIndex
READ MORE
July 14, 2026 at 1:03 AM
Open-source tool, closed-door panic, and ransomware’s favorite public service
PANIC 68% | Lag 27.91h | AdaptixC2 is being linked to ransomware activity, which means a legitimate red-team style framework
#AfterShockIndex
READ MORE
July 9, 2026 at 6:17 PM
A Bing search for OpManager ended in Akira ransomware - Bumblebee side-loaded into the UAC prompt. https://intel.threadlinqs.com/threat/TL-2026-1135 #ThreatIntel #Bumblebee #AdaptixC2 #Akira
July 6, 2026 at 5:38 PM
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

huntaegis.com
July 3, 2026 at 8:34 PM
📢 BumbleBee et AdaptixC2 utilisés pour déployer le ransomware Akira via SEO poisoning
📝 ## 🔍 Contexte

Rapport d'incident publié le 29 juin 2026 par T…
https://cyberveille.ch/posts/2026-07-01-bumblebee-et-adaptixc2-utilises-pour-deployer-le-ransomware-akira-via-seo-poisoning/ #AdaptixC2 #Cyberveille
July 1, 2026 at 10:30 AM
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

arc-codex.com
July 1, 2026 at 4:02 AM
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira https://packetstorm.news/news/view/42184 #news
June 30, 2026 at 7:17 PM
BumbleBee and AdaptixC2 Deliver Akira Ransomware Through Bing SEO Poisoning
gbhackers.com/bumblebee-an...
BumbleBee and AdaptixC2 Deliver Akira Ransomware Through Bing SEO Poisoning
BumbleBee and AdaptixC2 are being used in a highly efficient intrusion chain that starts with Bing SEO poisoning and ends with Akira ransomware deployment.
gbhackers.com
June 30, 2026 at 1:04 PM
BingのSEOポイズニングを起点にBumbleBeeとAdaptixC2がAkiraランサムウェアを展開

BumbleBeeとAdaptixC2が、BingのSEOポイズニングに始まりAkiraランサムウェアの展開で終わる、極めて効率的な侵入チェーンに悪用されています。信頼性の高い検索トラフィックが、企業への侵害経路として利用されるようになっている実態が浮き彫りになりました。 このキャンペーンが注目される理由は、個々の手...
BingのSEOポイズニングを起点にBumbleBeeとAdaptixC2がAkiraランサムウェアを展開
BumbleBeeとAdaptixC2が、BingのSEOポイズニングに始まりAkiraランサムウェアの展開で終わる、極めて効率的な侵入チェーンに悪用されています。信頼性の高い検索トラフィックが、企業への侵害経路として利用されるようになっている実態が浮き彫りになりました。 このキャンペーンが注目される理由は、個々の手
blackhatnews.tokyo
June 30, 2026 at 12:41 PM
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira - The DFIR Report
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira - The DFIR Report
thedfirreport.com
June 30, 2026 at 6:39 AM