Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
2026-04-18T20:51:48Z•cc2a745d32d9e001e32f98f392c838bf7349231486528edb2d76ada0dce0224e
BlueHammerDDoSDDoS-for-hireDraftKingsGrinexIoT botnetMicrosoft DefenderMiraiNexcoriumOperation PowerOFFQEMURedSunTBK DVRTP-LinkUnDefendcredential stuffingcryptocurrency exchangecryptojacking/theftdomain seizures','3 million accounts'law enforcementmalwareprivilege escalationransomwarevirtual machine evasionzero-day
What happened
Multiple security developments: attackers increasingly hide malware inside QEMU virtual machines to evade detection and deploy ransomware; a Mirai variant called Nexcorium exploits a TBK DVR flaw (and end-of-life TP‑Link routers) to build IoT botnets for DDoS; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited for privilege escalation, with two still unpatched; Kyrgyz crypto exchange Grinex halted operations after a $13.7M theft it blames on foreign intelligence; a DraftKings credential‑stuffing perpetrator was sentenced to 30 months and ordered to pay ~$1.4M
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cc2a745d32d9e001e32f98f392c838bf7349231486528edb2d76ada0dce0224e
- Enrichment time
- 2026-04-18T20:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.