Network tunneling with… QEMU?
ID: 8bd943f1-e865-5741-abb6-17a7cb03dabe
STIX ID: report--8bd943f1-e865-5741-abb6-17a7cb03dabe
Feed Name: Securelist by Kaspersky
Date Published: 2024-03-05
Date Updated: 2026-04-29
Author: Grigory Sablin, Alexander Rodchenko, Kirill Magaskin
Kaspersky researchers describe how adversaries abused QEMU virtualization to create a socket-based network tunnel between a compromised internal host and an attacker-controlled server, enabling remote access to otherwise isolated systems (demonstrated by successful RDP to an internal host). The report documents the QEMU command-line options used (-netdev user/socket/hubport, -nographic, -m 1M), analyzes the unencrypted encapsulated traffic and a method to extract tunneled PCAPs (editcap), reproduces the technique in a lab, and notes IDS detection with the signature Backdoor.Agent.QEMU.C&C.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
