A new threat technique has been identified in which cybercriminals are exploiting QEMU, a legitimate open-source virtualization tool, to create hidden virtual machines that allow them to steal data and spread malware while evading detection.
QEMU is widely used in enterprise and development environments for hardware emulation and virtualization purposes. However, threat actors have found ways to abuse its legitimate functionality to establish covert infrastructure within compromised networks.
By deploying hidden virtual machines through QEMU, attackers are able to operate within a target environment without triggering traditional security alerts. Because QEMU is a trusted and commonly used tool, its activity may not immediately raise red flags for security teams or automated detection systems.
This approach allows malicious actors to maintain persistence inside a victim’s network, exfiltrate sensitive data, and laterally move to spread malware across connected systems — all while remaining concealed beneath the cover of what appears to be legitimate software activity.
The use of legitimate tools for malicious purposes, often referred to as ‘living off the land’ tactics, continues to be a growing challenge for cybersecurity defenders. When attackers repurpose trusted applications like QEMU, it becomes significantly harder for security solutions to distinguish between normal operations and malicious behavior.
Organizations are advised to closely monitor the use of virtualization tools within their environments, implement strict application control policies, and ensure that behavioral analytics are in place to detect anomalous activity — even when it originates from trusted software.
As this threat vector continues to evolve, cybersecurity teams must remain vigilant and proactive in auditing the tools and processes running within their infrastructures.
—
*Source: Security Affairs — https://securityaffairs.com/190982/security/hidden-vms-how-hackers-leverage-qemu-to-stealthily-steal-data-and-spread-malware.html*