logo

Attacker Hides Malicious Activity in Emulated Linux Environment

ID: 04f039d0-8e2c-55a0-a442-96efa114188f

STIX ID: report--04f039d0-8e2c-55a0-a442-96efa114188f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-11-05

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers at Securonix uncovered a novel campaign named CRON#TRAP where attackers deploy a QEMU-emulated Tiny Core Linux VM (PivotBox) via a large phishing ZIP; the VM contains a preconfigured Chisel-based backdoor that automatically connects to a hardcoded U.S. C2, enabling covert reconnaissance, tooling deployment, SSH key-based persistence, and data exfiltration. The report highlights the technique's novelty and stealth, outlines observed commands and behaviors from the emulated environment, and recommends user training, application whitelisting, endpoint monitoring, and detection of unconventional QEMU execution and persistent SSH connections as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.