logo

QEMU Emulator Exploited as Tunneling Tool to Breach Company Network

ID: 8660e651-8336-51a4-b934-ba216487bed6

STIX ID: report--8660e651-8336-51a4-b934-ba216487bed6

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2024-03-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Kaspersky researchers observed threat actors using the QEMU open-source hardware emulator as a covert tunneling mechanism in an attack against a large unnamed company: attackers created virtual network and socket interfaces with QEMU to tunnel traffic from an internal, internet-restricted host to a pivot host with internet access, which then connected to an attacker-controlled cloud server. This novel use of legitimate software underscores adversaries' growing use of benign tools to blend malicious activity and highlights the need for layered detection beyond endpoint protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.