logo

Windows infected with backdoored Linux VMs in new phishing attacks

ID: bdfa4967-20b1-58e9-9119-4e4c00ab6ecb

STIX ID: report--bdfa4967-20b1-58e9-9119-4e4c00ab6ecb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A new phishing campaign dubbed 'CRON#TRAP' sends a 285MB ZIP (masquerading as a OneAmerica survey) that installs a QEMU-hosted TinyCore Linux VM on Windows; the VM contains a Chisel-based backdoor providing persistent, stealthy C2 over WebSockets/SSH, interactive host shells, file management, and exfiltration while evading host detection because QEMU is a signed legitimate binary. The report outlines the delivery chain, persistence via bootlocal.sh and SSH keys, examples of attacker commands, and recommends blocking or monitoring qemu.exe from user folders and disabling virtualization on critical systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.