logo

Hiding in the Shadows: Covert Tunnels via QEMU Virtualization

ID: be99f2d8-b09d-5264-bba9-902dc8c05d1d

STIX ID: report--be99f2d8-b09d-5264-bba9-902dc8c05d1d

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-10-02

Date Updated: 2026-05-01

...
...

TrustedSec investigated an intrusion where an attacker used a Microsoft Teams vishing call and Quick Assist/Zoho Meeting to convince a user to download artifacts that deployed portable QEMU VMs (Tiny Core Linux) on the host. The attacker used those VMs to attempt persistence (editing bootlocal.sh and filetool.lst), install OpenSSH, and create a reverse SSH tunnel to external IPs to maintain covert access; the report includes filenames, MD5 hashes, and attacker-controlled IPs as IOCs and recommends reimaging, credential resets, and controls on remote tools and virtualization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.