Payouts King ransomware uses QEMU VMs to bypass endpoint security
2026-04-18T13:23:27Z•65d1ed0222eb28da90790a5da622c98a94de009c5d011b70adc143cfe127ab07
AI-voice-phishingATHRApache ActiveMQCISADDoSHuggingFaceMarimoMicrosoft DefenderNKAbuseOT/ICSOperation PowerOFFPayouts KingQEMURedSunWindows privilege escalationZionSiphonbackdoorendpoint-evasionphishingransomwarereverse-SSHvirtualizationvishingwater-treatmentzero-day
What happened
A batch of BleepingComputer reports highlights a surge in active exploitation and novel attack techniques: Payouts King ransomware is abusing QEMU to run hidden VMs as a reverse-SSH backdoor to evade endpoint security; CISA warns of active exploitation of a high-severity Apache ActiveMQ flaw; multiple recently leaked Windows zero-days (including a Microsoft Defender “RedSun” PoC) are being used to gain SYSTEM privileges. Additional notable items include a critical Marimo notebook vulnerability used to deploy NKAbuse malware from Hugging Face, ZionSiphon OT malware targeting water treatment, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 65d1ed0222eb28da90790a5da622c98a94de009c5d011b70adc143cfe127ab07
- Enrichment time
- 2026-04-18T13:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.