logo

QEMU abused to evade detection and enable ransomware delivery

ID: 548a7901-1d5e-59a8-97a9-b3627fd18f7f

STIX ID: report--548a7901-1d5e-59a8-97a9-b3627fd18f7f

Feed Name: Sophos Blogs

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-30

...
...

Sophos warns of an uptick in threat actors abusing QEMU and hypervisor-based virtualization to run hidden VMs that host tooling for covert remote access, credential harvesting, lateral movement, and ransomware. The report documents two campaigns—STAC4713 (linked to PayoutsKing/GOLD ENCOUNTER) and STAC3725—that use scheduled tasks, reverse SSH tunnels, ScreenConnect implants, and exploited CVEs to maintain persistence and exfiltrate data, and provides IOCs and recommended detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.