logo

Network tunneling with… QEMU?

ID: 8bd943f1-e865-5741-abb6-17a7cb03dabe

STIX ID: report--8bd943f1-e865-5741-abb6-17a7cb03dabe

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2024-03-05

Date Updated: 2026-04-29

Author: Grigory Sablin, Alexander Rodchenko, Kirill Magaskin

...
...

Kaspersky researchers describe how adversaries abused QEMU virtualization to create a socket-based network tunnel between a compromised internal host and an attacker-controlled server, enabling remote access to otherwise isolated systems (demonstrated by successful RDP to an internal host). The report documents the QEMU command-line options used (-netdev user/socket/hubport, -nographic, -m 1M), analyzes the unencrypted encapsulated traffic and a method to extract tunneled PCAPs (editcap), reproduces the technique in a lab, and notes IDS detection with the signature Backdoor.Agent.QEMU.C&C.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.