logo

Virtualization for Defense Evasion: Hiding Tracks

ID: 35337965-f8ca-5b3f-9288-6264c52b9ea9

STIX ID: report--35337965-f8ca-5b3f-9288-6264c52b9ea9

Feed Name: ReliaQuest Blog

Threat Score
60/100

Date Published: 2023-07-06

Date Updated: 2026-04-29

...
...

This report explains how threat actors use host-hosted virtualization (particularly Type 2 hypervisors) to evade detection by creating and operating guest virtual machines on compromised endpoints. It covers the attack chain—image download/ingress, hypervisor installation, VM configuration and control, and VM-originated C2—provides observable indicators (e.g., unusual image downloads, hypervisor installer artifacts, process attribution of network traffic), and recommends hunting, baselining virtualization usage, and blocking unauthorized hypervisors as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.