Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware
2026-04-19T08:51:51Z•d00f23c04b6a6c8b5b40b54ead9b5b9f4586f74a1c60549479affac0efa119fc
Apache ActiveMQBlueHammerCISA KEVCVE-2026-34197Cisco vulnerabilities','Identity Services','Webex'DDoSGrinexIoT botnetMicrosoft DefenderMiraiNexcoriumQEMURedSunTBK DVRTP-Link (EOL)UnDefendZionSiphoncryptocurrency exchangehidden VMsindustrial control systemsmalwareransomwarevirtualization abusewater sectorzero-day
What happened
Collection of mid-April 2026 security incidents and research: Sophos warns attackers are abusing QEMU to run hidden VMs for stealthy malware, data theft and ransomware deployment; Fortinet reports a Nexcorium Mirai variant exploiting TBK DVR flaws and EOL TP-Link routers for DDoS botnets; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited to gain elevated access (two still unpatched); Kyrgyz exchange Grinex halted operations after a $13.7M theft; ZionSiphon malware targets Israeli water systems; CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to its KEV;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d00f23c04b6a6c8b5b40b54ead9b5b9f4586f74a1c60549479affac0efa119fc
- Enrichment time
- 2026-04-19T08:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.