A highly advanced malware campaign has emerged, exploiting search engine optimization (SEO) poisoning on Microsoft Bing to distribute the infamous Bumblebee malware to unaware users.
Uncovered in May 2025, this operation targets individuals searching for niche software, highlighting a troubling shift in how malware is spread through manipulated search engine results.
Bumblebee, a downloader malware first detected in 2022, is believed to be associated with ransomware groups due to its links with the Conti hacking collective. Known for its precision and effectiveness, Bumblebee has been delivered through a range of tactics, including phishing emails, infected documents, and now, this SEO poisoning method.
In this new tactic, cybercriminals have crafted counterfeit websites that closely mimic legitimate software packages. By tampering with Bing’s search ranking algorithms, they manage to place these fake sites at the top of search results, tricking users into downloading malicious content.
Cyjax researchers uncovered this attack after spotting a cluster of deceptive download sites targeting those seeking specific software. The campaign primarily targets two tools: WinMTR, a network diagnostics program, and Milestone XProtect, a video management software used in surveillance applications.

Malicious websites have managed to claim the top spots in search results, tricking users into visiting harmful sites (Source – CYJAX).
Both legitimate applications, commonly used in technical and security-focused sectors, hint at a targeted approach aimed at developers and IT professionals.
The attack leverages a sophisticated form of typosquatting, in which fake domains closely resemble trusted ones. For example, the real “winmtr.net” is impersonated by “winmtr.org,” while “milestonesys.com” is copied as “milestonesys.org.”
Both counterfeit domains are hosted on the same server under Truehost Cloud in Nairobi, suggesting a unified operation by a single group of cybercriminals.
Infection Flow Breakdown
The malware distribution begins when unsuspecting users click on download links from these fraudulent websites. They are then directed to malicious MSI installers, hosted on the domain “software-server[.]online,” which silently infect the victim’s system.

Execution Process of Bumblebee Malware (Source – CYJAX)
Upon being triggered through msiexec[.]exe, the installer deploys both the genuine software (e.g., winmtr.exe) and harmful elements. These include a Windows binary called icardagt.exe, which masquerades as legitimate, and a malicious DLL file named version.dll.
As illustrated in the execution sequence (Figure 1), the malware operates covertly by launching the authentic application while also loading the malicious DLL in the background. Despite utilizing an expired certificate from January 2010, the icardagt.exe file runs version.dll, which then activates the Bumblebee malware.
Once executed, Bumblebee establishes communication with a variety of command and control (C2) servers, all of which use the “.life” top-level domain (TLD).
This campaign marks a noticeable departure from previous Bumblebee SEO poisoning operations, which primarily targeted widely-used applications like Zoom, Cisco AnyConnect, and ChatGPT installers.
The shift toward targeting lesser-known technical software suggests a deliberate attempt to compromise environments with users who possess higher system privileges, creating favorable conditions for deeper network infiltration and potential data exfiltration.




