logo

The Detection & Response Chronicles: Covert Operations Through QEMU

ID: 296fa032-e39a-56af-8524-1c2d4ebac764

STIX ID: report--296fa032-e39a-56af-8524-1c2d4ebac764

Feed Name: NVISO Labs

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Stamatis Chatzimangou

...
...

This NVISO report describes how adversaries abused QEMU virtualization to run malicious tooling (Adaptix C2) inside guest VMs and use SSH and QEMU networking features to tunnel C2 traffic and access internal networks while evading host-based detections; the write-up includes command examples, persistence via cron, tunneling configurations, and recommended detection/hunting KQL queries for identifying suspicious QEMU use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.