Payouts King ransomware uses QEMU VMs to bypass endpoint security

2026-04-18T13:23:27Z65d1ed0222eb28da90790a5da622c98a94de009c5d011b70adc143cfe127ab07
AI-voice-phishingATHRApache ActiveMQCISADDoSHuggingFaceMarimoMicrosoft DefenderNKAbuseOT/ICSOperation PowerOFFPayouts KingQEMURedSunWindows privilege escalationZionSiphonbackdoorendpoint-evasionphishingransomwarereverse-SSHvirtualizationvishingwater-treatmentzero-day

What happened

A batch of BleepingComputer reports highlights a surge in active exploitation and novel attack techniques: Payouts King ransomware is abusing QEMU to run hidden VMs as a reverse-SSH backdoor to evade endpoint security; CISA warns of active exploitation of a high-severity Apache ActiveMQ flaw; multiple recently leaked Windows zero-days (including a Microsoft Defender “RedSun” PoC) are being used to gain SYSTEM privileges. Additional notable items include a critical Marimo notebook vulnerability used to deploy NKAbuse malware from Hugging Face, ZionSiphon OT malware targeting water treatment, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
65d1ed0222eb28da90790a5da622c98a94de009c5d011b70adc143cfe127ab07
Enrichment time
2026-04-18T13:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Payouts King ransomware uses QEMU VMs to bypass endpoint security · Baitaphish