The Detection & Response Chronicles: Covert Operations Through QEMU
ID: 296fa032-e39a-56af-8524-1c2d4ebac764
STIX ID: report--296fa032-e39a-56af-8524-1c2d4ebac764
Feed Name: NVISO Labs
Threat Score
This NVISO report describes how adversaries abused QEMU virtualization to run malicious tooling (Adaptix C2) inside guest VMs and use SSH and QEMU networking features to tunnel C2 traffic and access internal networks while evading host-based detections; the write-up includes command examples, persistence via cron, tunneling configurations, and recommended detection/hunting KQL queries for identifying suspicious QEMU use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
