logo

Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

ID: 9e09178d-49dd-5ed0-a49c-197879d449e2

STIX ID: report--9e09178d-49dd-5ed0-a49c-197879d449e2

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Sophos analysts report two active campaigns (STAC4713 and STAC3725) that abuse QEMU to run hidden virtual machines under the SYSTEM account to evade endpoint defenses, harvest Active Directory credentials, and stage ransomware—STAC4713 is tied to PayoutsKing/GOLD ENCOUNTER and uses scheduled tasks, disguised virtual disk files, and SSH tunneling, while STAC3725 exploits CitrixBleed2 to install ScreenConnect and compile tools inside a QEMU VM for credential theft and reconnaissance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.