Hiding in the Shadows: Covert Tunnels via QEMU Virtualization
ID: be99f2d8-b09d-5264-bba9-902dc8c05d1d
STIX ID: report--be99f2d8-b09d-5264-bba9-902dc8c05d1d
Feed Name: TrustedSec blog
TrustedSec investigated an intrusion where an attacker used a Microsoft Teams vishing call and Quick Assist/Zoho Meeting to convince a user to download artifacts that deployed portable QEMU VMs (Tiny Core Linux) on the host. The attacker used those VMs to attempt persistence (editing bootlocal.sh and filetool.lst), install OpenSSH, and create a reverse SSH tunnel to external IPs to maintain covert access; the report includes filenames, MD5 hashes, and attacker-controlled IPs as IOCs and recommends reimaging, credential resets, and controls on remote tools and virtualization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
