QEMU Emulator Exploited as Tunneling Tool to Breach Company Network
ID: 8660e651-8336-51a4-b934-ba216487bed6
STIX ID: report--8660e651-8336-51a4-b934-ba216487bed6
Feed Name: The Hacker News
Kaspersky researchers observed threat actors using the QEMU open-source hardware emulator as a covert tunneling mechanism in an attack against a large unnamed company: attackers created virtual network and socket interfaces with QEMU to tunnel traffic from an internal, internet-restricted host to a pivot host with internet access, which then connected to an attacker-controlled cloud server. This novel use of legitimate software underscores adversaries' growing use of benign tools to blend malicious activity and highlights the need for layered detection beyond endpoint protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
