logo

Payouts King ransomware uses QEMU VMs to bypass endpoint security

ID: 8ff7050d-27aa-55c3-a2f6-1fba8e767404

STIX ID: report--8ff7050d-27aa-55c3-a2f6-1fba8e767404

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report details Payouts King (STAC4713) and a related STAC3725 campaign that deploy hidden QEMU-based Alpine Linux VMs on compromised hosts to bypass endpoint security, create reverse SSH tunnels, and stage credential harvesting and data exfiltration. Observed TTPs include exploitation of NetScaler (CitrixBleed 2 CVE‑2025‑5777) and SolarWinds Web Help Desk (CVE‑2025‑26399), use of scheduled tasks (e.g., ‘TPMProfiler’) to run VMs as SYSTEM, AD reconnaissance and hive harvesting, toolsets installed inside VMs (AdaptixC2, Chisel, Rclone, Impacket, Metasploit), and ransomware operations with AES-256(RSA-4096) encryption and extortion portals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.