logo

Beyond the bomb: When adversaries bring their own virtual machine for persistence

ID: 8bbc8ba1-2092-5d72-81ad-178d5a99f740

STIX ID: report--8bbc8ba1-2092-5d72-81ad-178d5a99f740

Feed Name: Red Canary

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-29

Author: Tony Lambert

...
...

Red Canary Intelligence describes an intrusion where attackers used an email-bombing distraction and a vishing call to trick a user into granting Quick Assist, then introduced a QEMU VM running Windows 7 containing Sliver implants, a QDoor-like backdoor, and ScreenConnect to perform internal scanning, persistence, and C2 communications; the report details forensic findings, recovered artifacts, network indicators, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.