惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
Jina AI
Jina AI
雷峰网
雷峰网
博客园_首页
WordPress大学
WordPress大学
博客园 - 司徒正美
爱范儿
爱范儿
博客园 - 聂微东
IT之家
IT之家
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
博客园 - Franky
V
V2EX
GbyAI
GbyAI
阮一峰的网络日志
阮一峰的网络日志

Latest from TechRadar in Pro

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… I tried 7 free MTD software – now I've ranked my top picks as a freelancer Jackery McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… The new engineering playbook: how AI design copilots are reshaping product development Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts Europe wants tech sovereignty but is this realistic? Enterprise AI governance cannot live in a prompt. So where is the safety net? Why 2026 is the year of flexibility without friction: solving the multi-platform crisis OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap LaLiga uses AI to fight illegal streaming that costs its clubs $800m a year Intel and Google expand long-term chip partnership to power AI systems 'Chatbots respond not just to what you ask, but how you ask it': Report finds AI agents might be sucking up to… 'Smartphones have physical limitations': Report explains why AI is kickstarting a billion-dollar hardware arms… 'I’m pretty sure actually we really do not need to work for five days' Zoom CEO calls for end of traditional work schedules — says 3-day working week should become the norm 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these…
“Essentially invisible:” How hackers 'trojan-horsed' QEMU...
Wayne Williams · 2026-04-21 · via Latest from TechRadar in Pro

  • Hidden virtual machines allow attackers to bypass endpoint security and remain undetected
  • Attackers used trusted virtualization tools and built-in software to disguise malicious activity
  • Sophos links campaigns using QEMU to ransomware deployment and long-term network access

Attackers are increasingly hiding malicious tools inside virtual machines to slip past security controls.

Sophos analysts say the approach relies on virtualization software that security systems often treat as legitimate activity.

In recent incidents, attackers used QEMU, an open-source machine emulator and virtualizer, to run hidden environments where malicious activity remained largely invisible to endpoint defenses and left minimal evidence on the host system.

A growing evasion trend

Sophos notes that while the method is not new, it has gained traction again, with two active campaigns, tracked as STAC4713 and STAC3725, identified since the end of last year.

In the STAC4713 campaign, attackers created a scheduled task named TPMProfiler to launch a hidden QEMU virtual machine under system-level privileges.

The virtual machine used disguised disk images, first appearing as database files and later masquerading as dynamic link libraries.

Once launched, the virtual machine established reverse SSH tunnels that created covert remote access channels, allowingattackers to run tools and collect domain credentials without exposing activity to traditional security tools.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sophos investigators also observed attackers using built-in Windows utilities such as Microsoft Paint, Notepad, and Edge for file access and network discovery. This relied heavily on trusted software to blend malicious actions into routine system behavior.

Older intrusions tied to the campaign used exposed VPN systems without multi-factor authentication, while later incidents exploited a SolarWinds Web Help Desk vulnerability tracked as CVE-2025-26399. These varied entry points show attackers adjusting their tactics depending on available weaknesses.

Sophos links the STAC4713 campaign to PayoutsKing ransomware, which focuses on encrypting virtualized environments.

The group behind the ransomware appears to target hypervisors and deploy tools that can operate across VMware and ESXi systems.

The second campaign, STAC3725, relied on exploiting the CitrixBleed2 vulnerability to gain initial access before installing remote access software.

Attackers then launched a QEMU virtual machine to manually assemble attack tools for credential theft and network reconnaissance.

Rather than delivering ready-made payloads, attackers compiled their toolsets inside the virtual machine after gaining access. That approach allowed them to customize attacks and reduce the chance of detection by signature-based defenses.

Sophos warns that hiding activity inside virtual machines represents a growing evasion trend. Strong endpoint protection, network monitoring, and timely patching of exposed systems critical to reducing risk.


Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.