Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
ID: 8279fde8-c217-5c3f-b477-bbf994b25728
STIX ID: report--8279fde8-c217-5c3f-b477-bbf994b25728
Feed Name: Security Affairs
Sophos researchers report an increase in attackers abusing QEMU and other virtualization platforms to run malware inside hidden VMs, enabling stealthy credential theft, data exfiltration, and deployment of PayoutsKing ransomware; two campaigns (STAC4713 linked to GOLD ENCOUNTER and STAC3725) leveraged CVE-2025-26399, CitrixBleed2, scheduled tasks, reverse SSH tunnels, and legitimate tools to evade detection, maintain persistence, and facilitate follow-on ransomware or data theft—Sophos provides mitigations and indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
