QEMU abused to evade detection and enable ransomware delivery
ID: 548a7901-1d5e-59a8-97a9-b3627fd18f7f
STIX ID: report--548a7901-1d5e-59a8-97a9-b3627fd18f7f
Feed Name: Sophos Blogs
Threat Score
Sophos warns of an uptick in threat actors abusing QEMU and hypervisor-based virtualization to run hidden VMs that host tooling for covert remote access, credential harvesting, lateral movement, and ransomware. The report documents two campaigns—STAC4713 (linked to PayoutsKing/GOLD ENCOUNTER) and STAC3725—that use scheduled tasks, reverse SSH tunnels, ScreenConnect implants, and exploited CVEs to maintain persistence and exfiltrate data, and provides IOCs and recommended detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
