Threat actors have been seen using the open-source QEMU hardware emulator as a tunneling tool to connect to the infrastructure of an unidentified “large company” in a cyberattack.
Although adversaries have successfully exploited several legal tunneling tools, including Chisel, FRP, ligolo, ngrok, and Plink, this research represents the first time a QEMU has been used for this kind of activity.
We discovered that QEMU allowed connections between virtual machines: according to Kaspersky researchers Grigory Sablin, Alexander Rodchenko, and Kirill Magaskin, the -netdev option builds network devices (backend) that can then connect to the virtual machines read more QEMU Emulator Exploited as Tunneling Tool to Breach Company Network.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
