Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware

2026-04-19T08:51:51Zd00f23c04b6a6c8b5b40b54ead9b5b9f4586f74a1c60549479affac0efa119fc
Apache ActiveMQBlueHammerCISA KEVCVE-2026-34197Cisco vulnerabilities','Identity Services','Webex'DDoSGrinexIoT botnetMicrosoft DefenderMiraiNexcoriumQEMURedSunTBK DVRTP-Link (EOL)UnDefendZionSiphoncryptocurrency exchangehidden VMsindustrial control systemsmalwareransomwarevirtualization abusewater sectorzero-day

What happened

Collection of mid-April 2026 security incidents and research: Sophos warns attackers are abusing QEMU to run hidden VMs for stealthy malware, data theft and ransomware deployment; Fortinet reports a Nexcorium Mirai variant exploiting TBK DVR flaws and EOL TP-Link routers for DDoS botnets; three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) are being exploited to gain elevated access (two still unpatched); Kyrgyz exchange Grinex halted operations after a $13.7M theft; ZionSiphon malware targets Israeli water systems; CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to its KEV;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d00f23c04b6a6c8b5b40b54ead9b5b9f4586f74a1c60549479affac0efa119fc
Enrichment time
2026-04-19T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.