Payouts King ransomware uses QEMU VMs to bypass endpoint security
ID: 8ff7050d-27aa-55c3-a2f6-1fba8e767404
STIX ID: report--8ff7050d-27aa-55c3-a2f6-1fba8e767404
Feed Name: Bleeping Computer
The report details Payouts King (STAC4713) and a related STAC3725 campaign that deploy hidden QEMU-based Alpine Linux VMs on compromised hosts to bypass endpoint security, create reverse SSH tunnels, and stage credential harvesting and data exfiltration. Observed TTPs include exploitation of NetScaler (CitrixBleed 2 CVE‑2025‑5777) and SolarWinds Web Help Desk (CVE‑2025‑26399), use of scheduled tasks (e.g., ‘TPMProfiler’) to run VMs as SYSTEM, AD reconnaissance and hive harvesting, toolsets installed inside VMs (AdaptixC2, Chisel, Rclone, Impacket, Metasploit), and ransomware operations with AES-256(RSA-4096) encryption and extortion portals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
