Windows infected with backdoored Linux VMs in new phishing attacks
ID: bdfa4967-20b1-58e9-9119-4e4c00ab6ecb
STIX ID: report--bdfa4967-20b1-58e9-9119-4e4c00ab6ecb
Feed Name: Bleeping Computer
A new phishing campaign dubbed 'CRON#TRAP' sends a 285MB ZIP (masquerading as a OneAmerica survey) that installs a QEMU-hosted TinyCore Linux VM on Windows; the VM contains a Chisel-based backdoor providing persistent, stealthy C2 over WebSockets/SSH, interactive host shells, file management, and exfiltration while evading host detection because QEMU is a signed legitimate binary. The report outlines the delivery chain, persistence via bootlocal.sh and SSH keys, examples of attacker commands, and recommends blocking or monitoring qemu.exe from user folders and disabling virtualization on critical systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
