Payouts King ransomware uses QEMU VMs to bypass endpoint security
2026-04-18T07:23:28Z•9b5e5ac6d8950620aa699c51e42ffe3347b93734ba59fb91f69a5c5d13c27e18
AI voice phishingATHRApache ActiveMQDDoSGrinexMarimoMicrosoft DefenderNKAbuseOT sabotageOperation PowerOFFPayouts KingQEMURedSunWindows privilege escalationZionSiphonactive exploitationcryptocurrency exchange hackendpoint evasionoperational technologyransomwarereverse SSH backdoorthreat intelligencevirtual machinesvishingzero-day
What happened
Multiple high-risk incidents and active exploitation campaigns were reported: Payouts King ransomware is running hidden QEMU virtual machines and a reverse-SSH backdoor to bypass endpoint security; CISA flagged an actively exploited high-severity Apache ActiveMQ vulnerability; threat actors are exploiting recently leaked Windows zero-days and a Microsoft Defender “RedSun” PoC that can grant SYSTEM; a critical Marimo notebook flaw is being used to deploy NKAbuse malware from Hugging Face; and ZionSiphon malware is targeting water treatment/desalination OT environments. Additional notable events
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9b5e5ac6d8950620aa699c51e42ffe3347b93734ba59fb91f69a5c5d13c27e18
- Enrichment time
- 2026-04-18T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.