Payouts King ransomware uses QEMU VMs to bypass endpoint security

2026-04-18T07:23:28Z9b5e5ac6d8950620aa699c51e42ffe3347b93734ba59fb91f69a5c5d13c27e18
AI voice phishingATHRApache ActiveMQDDoSGrinexMarimoMicrosoft DefenderNKAbuseOT sabotageOperation PowerOFFPayouts KingQEMURedSunWindows privilege escalationZionSiphonactive exploitationcryptocurrency exchange hackendpoint evasionoperational technologyransomwarereverse SSH backdoorthreat intelligencevirtual machinesvishingzero-day

What happened

Multiple high-risk incidents and active exploitation campaigns were reported: Payouts King ransomware is running hidden QEMU virtual machines and a reverse-SSH backdoor to bypass endpoint security; CISA flagged an actively exploited high-severity Apache ActiveMQ vulnerability; threat actors are exploiting recently leaked Windows zero-days and a Microsoft Defender “RedSun” PoC that can grant SYSTEM; a critical Marimo notebook flaw is being used to deploy NKAbuse malware from Hugging Face; and ZionSiphon malware is targeting water treatment/desalination OT environments. Additional notable events

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9b5e5ac6d8950620aa699c51e42ffe3347b93734ba59fb91f69a5c5d13c27e18
Enrichment time
2026-04-18T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.