Payouts King ransomware uses QEMU VMs to bypass endpoint security

2026-04-18T01:23:36Zfd2f32aa01678f7790715084239b3d28d220fd4f666111dee3b00257ed15ed69
ai-voice-phishingapache-activemqathrbackdoorcardingcisacryptocurrency-hackddosendpoint-evasiongrinexhugging-facemarimomicrosoft-defendernkabuseoperation-poweroffoperational-technologypayouts-kingqemuransomwareredsUN-poCunderground-marketsvirtual-machinesvishingwindows-zero-dayzionsiphon

What happened

Multiple active threats and exploit developments: Payouts King ransomware is abusing QEMU to run hidden VMs via a reverse‑SSH backdoor to evade endpoint defenses; CISA warned of active exploitation of a long‑undetected, high‑severity Apache ActiveMQ flaw; several recently leaked Windows zero‑days (and a public PoC for Microsoft Defender “RedSun”) are being used to gain SYSTEM/elevated privileges; a critical Marimo notebook vulnerability has been abused to deploy NKAbuse from Hugging Face; ZionSiphon malware targets water‑treatment OT environments; a new AI‑enabled ATHR vishing platform automa‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fd2f32aa01678f7790715084239b3d28d220fd4f666111dee3b00257ed15ed69
Enrichment time
2026-04-18T01:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.