logo

Malicious use of virtual machine infrastructure

ID: 0281542c-e25d-5e89-8a17-ff1f6ca789f0

STIX ID: report--0281542c-e25d-5e89-8a17-ff1f6ca789f0

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-30

...
...

CTU researchers found that ISPsystem VMmanager distributes prebuilt Windows templates that embed static hostnames and system identifiers, causing thousands of VMs to expose identical hostnames (e.g., WIN-LIVFRVQFMKO, WIN-J9D866ESIJ2). Those hostnames appear widely across a few hosting providers and countries and have been linked to active ransomware and malware operations, bulletproof hosting advertisements, and exploitation activity, meaning template reuse is creating misleading shared infrastructure and enabling criminal use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.