Payouts King ransomware uses QEMU VMs to bypass endpoint security
2026-04-18T01:23:36Z•fd2f32aa01678f7790715084239b3d28d220fd4f666111dee3b00257ed15ed69
ai-voice-phishingapache-activemqathrbackdoorcardingcisacryptocurrency-hackddosendpoint-evasiongrinexhugging-facemarimomicrosoft-defendernkabuseoperation-poweroffoperational-technologypayouts-kingqemuransomwareredsUN-poCunderground-marketsvirtual-machinesvishingwindows-zero-dayzionsiphon
What happened
Multiple active threats and exploit developments: Payouts King ransomware is abusing QEMU to run hidden VMs via a reverse‑SSH backdoor to evade endpoint defenses; CISA warned of active exploitation of a long‑undetected, high‑severity Apache ActiveMQ flaw; several recently leaked Windows zero‑days (and a public PoC for Microsoft Defender “RedSun”) are being used to gain SYSTEM/elevated privileges; a critical Marimo notebook vulnerability has been abused to deploy NKAbuse from Hugging Face; ZionSiphon malware targets water‑treatment OT environments; a new AI‑enabled ATHR vishing platform automa‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fd2f32aa01678f7790715084239b3d28d220fd4f666111dee3b00257ed15ed69
- Enrichment time
- 2026-04-18T01:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.