Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware

2026-04-18T20:51:48Zcc2a745d32d9e001e32f98f392c838bf7349231486528edb2d76ada0dce0224e
BlueHammerDDoSDDoS-for-hireDraftKingsGrinexIoT botnetMicrosoft DefenderMiraiNexcoriumOperation PowerOFFQEMURedSunTBK DVRTP-LinkUnDefendcredential stuffingcryptocurrency exchangecryptojacking/theftdomain seizures','3 million accounts'law enforcementmalwareprivilege escalationransomwarevirtual machine evasionzero-day

What happened

Multiple security developments: attackers increasingly hide malware inside QEMU virtual machines to evade detection and deploy ransomware; a Mirai variant called Nexcorium exploits a TBK DVR flaw (and end-of-life TP‑Link routers) to build IoT botnets for DDoS; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited for privilege escalation, with two still unpatched; Kyrgyz crypto exchange Grinex halted operations after a $13.7M theft it blames on foreign intelligence; a DraftKings credential‑stuffing perpetrator was sentenced to 30 months and ordered to pay ~$1.4M

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cc2a745d32d9e001e32f98f392c838bf7349231486528edb2d76ada0dce0224e
Enrichment time
2026-04-18T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.