Payouts King ransomware uses QEMU VMs to bypass endpoint security

2026-04-17T19:23:32Zfe2c71a2b8ba169327cabffbd0551b3fa6f067859c9acae86b2b6bbd478a35a5
AI-voice-phishingATHRApache ActiveMQCISADDoSGrinex hack","carding-markets","underground-economy","patching-\Hugging FaceMarimoMicrosoft DefenderNKAbuseOT-malwareOperation PowerOFFPayouts KingQEMURedSunWindows privilege escalationZionSiphonbackdoorcryptocurrency-theftendpoint-bypassransomwarevirtualizationvishingwater-treatmentzero-day

What happened

Multiple high-risk incidents and active exploitations were reported: Payouts King ransomware is abusing QEMU to run hidden VMs as a reverse-SSH backdoor to evade endpoint controls; CISA warned of active exploitation of a high-severity Apache ActiveMQ vulnerability; several recently leaked Windows zero-days and a published Microsoft Defender "RedSun" PoC are being used to gain SYSTEM/elevated privileges; a critical Marimo notebook flaw is being abused to deploy NKAbuse malware from Hugging Face; and ZionSiphon malware targets water treatment OT environments. Additional notable developments: a $

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fe2c71a2b8ba169327cabffbd0551b3fa6f067859c9acae86b2b6bbd478a35a5
Enrichment time
2026-04-17T19:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.