Connect with us
DAPA Banner

Tech

Payouts King ransomware uses QEMU VMs to bypass endpoint security

Published

on

Payouts King ransomware uses QEMU VMs to bypass endpoint security

The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security.

QEMU is an open-source CPU emulator and system virtualization tool that allows users to run operating systems on a host computer as virtual machines (VMs).

Since security solutions on the host cannot scan inside the VMs, attackers can use them to execute payloads, store malicious files, and create covert remote access tunnels over SSH.

Wiz

For these reasons, QEMU has been abused in past operations from multiple threat actors, including the 3AM ransomware group, LoudMiner cryptomining, and ‘CRON#TRAP’ phishing.

Researchers at cybersecurity company Sophos documented two campaigns where attackers deployed QEMU as part of their arsenal and to collect domain credentials.

Advertisement

One campaign that Sophos tracks as STAC4713 was first observed in November 2025 and has been linked to the Payouts King ransomware operation.

The other, tracked as STAC3725, has been spotted in February this year and exploits the CitrixBleed 2 (CVE‑2025‑5777) vulnerability in NetScaler ADC and Gateway instances.

Running Alpine Linux VMs

Researchers note that the threat actors behind the STAC4713 campaign are associated with the GOLD ENCOUNTER threat group, which is known to target hypervisors and encryptors for VMware and ESXi environments.

According to Sophos, the malicious actor creates a scheduled task named ‘TPMProfiler’ to launch a hidden QEMU VM as SYSTEM.

Advertisement

They use virtual disk files disguised as databases and DLL files, and set up port forwarding to provide covert access to the infected host via a reverse SSH tunnel.

The VM runs Alpine Linux version 3.22.0 that includes attacker tools such as AdaptixC2, Chisel, BusyBox, and Rclone.

Sophos notes that initial access was achieved via exposed SonicWall VPNs, while exploitation of the SolarWinds Web Help Desk vulnerability CVE-2025-26399 was observed in more recent attacks.

In the post-infection phase, the threat actors used VSS (vssuirun.exe) to create a shadow copy, then used the print command over SMB to copy NTDS.dit, SAM, and SYSTEM hives to temp directories.

Advertisement

More recently observed incidents attributed to the threat actor relied on other initial access vectors. The researchers say that in an attack in February, GOLD ENCOUNTER used an exposed Cisco SSL VPN, and in March they posed as IT staff and tricked employees over Microsoft Teams into downloading and installing QuickAssist.

“In both instances, the threat actors used the legitimate ADNotificationManager.exe binary to sideload a Havoc C2 payload (vcruntime140_1.dll) and then leveraged Rclone to exfiltrate data to a remote SFTP location” – Sophos

According to a Zscaler report this week, Payouts King is likely tied to former BlackBasta affiliates, based on its use of similar initial access methods like spam bombing, Microsoft Teams phishing, and Quick Assist abuse.

The strain employs heavy obfuscation and anti-analysis mechanisms, establishes persistence via scheduled tasks, and terminates security tools using low-level system calls.

Advertisement

Payouts King encryption scheme uses AES-256 (CTR) with RSA-4096 with intermittent encryption for larger files. The dropped ransom notes point victims to leak sites on the dark web.

Payouts King ransomware extortion portal
Payouts King ransomware extortion portal
Source: BleepingComputer

The second campaign that Sophos observed (STAC3725), has been active since February and exploits the CitrixBleed 2 vulnerability to gain initial access to target environments.

After compromising NetScaler devices, the attackers deploy a ZIP archive containing a malicious executable that installs a service named ‘AppMgmt,’ creates a new local admin user (CtxAppVCOMService), and installs a ScreenConnect client for persistence.

The ScreenConnect client connects to a remote relay server and establishes a session with system privileges, then drops and extracts a QEMU package that runs a hidden Alpine Linux VM using a custom.qcow2 disk image.

Instead of using a pre-built toolkit, the attackers manually install and compile their tools, including Impacket, KrbRelayx, Coercer, BloodHound.py, NetExec, Kerbrute, and Metasploit, inside the VM.

Advertisement

Observed activity includes credential harvesting, Kerberos username enumeration, Active Directory reconnaissance, and staging data for exfiltration via FTP servers.

Sophos recommends that organizations look for unauthorized QEMU installations, suspicious scheduled tasks running with SYSTEM privileges, unusual SSH port forwarding, and outbound SSH tunnels on non-standard ports.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

This is Your Last Chance to Grab a Meta Quest 3S VR Headset at Today’s Prices

Published

on

Meta Quest 3S Price Increase Reasons to Buy 2026
Meta’s price increase for their Quest headsets was announced just yesterday, and begin on April 19th, providing users only a little window of time to buy now and avoid a larger bill for the same hardware. The Quest 3S with 128GB of storage is currently priced at $299.99, but will increase to $349.99 on Sunday, representing a $50 difference.



The extra cash is important, though, because these headsets already give a lot without any additional hardware. Simply slip one on and you’ll be able to play games ranging from small puzzle sessions to full-on adventures. You may watch movies on a screen that feels larger than the one in your living room. You can connect with pals in shared spaces, even if one of you is on the opposite side of the nation, and everything operates directly from the device, so no cables or a powerful computer are required.

One reason users prefer to stick with their units for longer than planned is that the library of material continues to grow. New titles are released all the time, and existing games and applications receive free upgrades that add new levels or features. You may use your Quest to transform your living room into a tiny gym or to get some work done in a distraction-free environment. There is something worthwhile in there, regardless of how you spend your time.


Now, both the Quest 3S and the Quest 3 work admirably, but they serve distinct purposes. The Quest 3S provides a decent starting point, with clear video and comfortable wear for regular usage, making it ideal for informal sessions. The good news is that the accessories will remain where they are, so you can upgrade to a nicer strap, supplementary battery pack, or carrying bag without breaking the budget or encountering any unpleasant surprises later.

Meta said the price increases are due to growing memory chip costs, which are hurting the whole electronics industry. Other industries are essentially consuming all of the memory chips available, raising prices and increasing production costs. As far as they can tell, there is no immediate resolution for this problem, so the current prices feel more like a temporary gift than the new normal.

Advertisement

Source link

Continue Reading

Tech

How One Builder 3D Printed a Complete Algae Production System

Published

on

3D-Printed Photobioreactor Algae Production
One builder showcases custom-built photobioreactor from start to finish, having printed the majority of its components on a conventional 3D printer sitting on a work surface. The final machine simply sits there silently day after day, converting water and light into useable biomass without the need for anyone to pay attention to it.



Spirulina fills the main chamber since the design ensures a consistent temperature, light, and air supply around the clock. A small initial amount of culture, roughly a gallon, expands over the next few weeks when fresh water and nutrients are introduced. The light enters from the sides, and there’s an air bubbler to keep everything mixed up and full of oxygen. Sensors are on the job, keeping an eye on things to ensure that the algae has enough to grow and reproduce swiftly, providing a few grams of dried biomass per week after the culture is fully established.


Bambu Lab A1 3D Printer, Support Multi-Color 3D Printing, High Speed & Precision, Full-Auto Calibration…
  • High-Speed Precision: Experience unparalleled speed and precision with the Bambu Lab A1 3D Printer. With an impressive acceleration of 10,000 mm/s…
  • Multi-Color Printing with AMS lite: Unlock your creativity with vibrant and multi-colored 3D prints. The Bambu Lab A1 3D printers make multi-color…
  • Full-Auto Calibration: Say goodbye to manual calibration hassles. The A1 3D printer takes care of all the calibration processes automatically…

Things begin with the Bambu Lab A1 printer laying down thermoplastic layers for the frame, tank supports, and custom fittings. Large pieces come together quickly due to automated calibration and the printer’s rapid speeds. The printed parts fit together nicely and snugly, requiring little more than a touch of tidying before assembling the entire device. Off-the-shelf pumps, lighting, and tubing are then inserted into the plastic skeleton, changing it into a sealed environment that retains the liquid inside without leaking everywhere.

3D-Printed Photobioreactor Algae Production
When everything is more or less upright, the electronics take over. A Raspberry Pi 5 serves as the main controller, with two Arduinos acting as task specialists. One Arduino is responsible for running the lights, heating, and bubbler on a regular basis. The second only handles the automated sampling procedure, which checks the acidity levels without allowing the sensors to run dry or deviate off course. A series of USB wires transmit basic text commands back and forth to keep the entire arrangement in sync.

3D-Printed Photobioreactor Algae Production
Measuring pH is particularly difficult since the probe must remain wet and clean between readings. So there’s a small rotating part that removes the lids off the storage vials, rinses the sensor in deionized water, and then moves it to grab a sample from the culture before returning it to the vial. A spinning pill inside a silicone tube attached to magnets to provide gentle stirring and minimize residue buildup. As a bonus, the same motion shuts up the vial, preventing evaporation. This all runs on its own tiny schedule and logs each outcome in case somebody wants to look it up later.

3D-Printed Photobioreactor Algae Production
Data appears on a touchscreen that looks like a control panel. At a glance, graphs indicate how light intensity decreases at the bottom of the tank as algae density increases and blocks more light. The temperature readings are always displayed directly in front of you. When harvest time approaches, when the light curve finally flattens out, signaling peak concentration, the system drains a section of the culture, filtering out the good stuff while allowing the remainder to continue growing. Once harvested, the material is spread out on trays, dries in a few hours, and is pulverized into a fine green powder that can be stored or used immediately as fish food.

3D-Printed Photobioreactor Algae Production
The biomass yield is currently around eight grams per week, which is sufficient to support a small aquaponic setup and reduce the need to purchase as much feed. Dried spirulina can also be stored for up to two years, providing a shelf-stable protein source right from your own backyard. And when your algae feed your fish, your fish waste fertilizes your plants, and your plant trimmings return to the algal culture, the entire system just keeps cycling round and round without any external assistance. Once the first culture is established, there is no need for additional inputs.

Advertisement

Source link

Continue Reading

Tech

India won't force Apple to preinstall its state-run app on iPhone after all

Published

on

India’s government has abandoned its proposal that would require smartphone manufacturers to preinstall the state-owned biometric identification app, Aadhaar, on phones.

Two rounded square app icons on a teal gradient background: left shows iOS text over abstract blue and teal shapes, right shows the App Store stylized A on bright blue.
India drops proposal mandating Apple preinstall national ID app

In November, India’s Ministry of Communications issued a directive ordering smartphone producers to preload Aadhaar on any phone sold within the country. The order would have affected Apple, Oppo, Vivo, and Xiaomi.
According to Reuters, India’s IT ministry has since reviewed the proposal and “is not in favour of mandating the pre-installation of the Aadhaar App on smartphones.” The ministry said the decision came after it held a “consultation with stakeholders from the electronics industry.”
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Tech

Making A Bronze Mirror From Scratch

Published

on

Although modern-day silvered glass mirrors have pretty much destroyed the market for bronze mirrors, these highly polished pieces of metal once were the pinnacle of mirror technology. Due to the laborious process required these mirrors saw use essentially only by the affluent. That said, how hard would it be to make a bronze mirror today with all of the modern technologies that even a hobbyist can acquire for their shed? Cue [Lundgren Bronze Studios] giving it a shot, starting by casting something flat-ish to start polishing.

Just getting that initial shape to start polishing is a chore, with hammering out the shape possibly being also a viable method. When casting metal it’s tricky to avoid having air bubbles and other defects forming, though using a sand mold seems to help a lot.

After you have the rough shape, polishing using power tools seems like cheating, but as you can see in the video even going from 50 to 8000 grit with a rotating disc left countless scratches. Amusingly, hand sanding did a much better job of removing the worst scratches, following which a polishing compound helped to bring out that literal mirror finish.

A quick glance at the Wikipedia entry for bronze mirrors shows that a tin-bronze alloy like speculum metal was used for thousands of years as it was much easier to polish to a good mirror finish. The metallurgy of what may seem like just a vanity item clearly goes deeper than just polishing up a metal surface.

Advertisement

Source link

Advertisement
Continue Reading

Tech

OpenAI Executive Kevin Weil Is Leaving the Company

Published

on

Kevin Weil, OpenAI’s former chief product officer who was recently tapped to build a new AI workspace for scientists, Prism, is leaving the company, WIRED has confirmed. Weil was previously an early executive leading product at Instagram.

“Today is my last day at OpenAI, as OpenAI for Science is being decentralized into other research teams,” Weil said in a social media post on Friday, shortly after WIRED reported his departure. “It’s been a mind-expanding two years, from Chief Product Officer to joining the research team and starting OpenAI for Science.”

Weil did not immediately respond to a request for comment from WIRED.

OpenAI is also sunsetting Prism, which the company launched as a web app in January to give scientists a better way to work with AI. The company is folding the roughly 10-person team behind it under OpenAI’s head of Codex, Thibault Sottiaux, and aims to incorporate Prism’s capabilities into its desktop Codex app. An OpenAI spokesperson confirmed the changes and tells WIRED this is part of the company’s effort to unify its business and product strategy. OpenAI has broader ambitions to turn Codex, its AI coding application, into an “everything app.”

Advertisement

Weil, who joined OpenAI in June 2024, announced last September that he would be starting a new initiative inside of the company called OpenAI for Science. Now, OpenAI is dispersing those employees throughout the company’s product, research, and infrastructure teams. An OpenAI spokesperson reiterated the company’s commitment to accelerating scientific discovery and says it’s one of the clearest ways AI can benefit humanity. Earlier on Friday, the company announced a new series of AI models—GPT-Rosalind—built to help life sciences researchers work faster.

OpenAI is trying to refocus the company around a few key areas, such as enterprise offerings and coding, as the company faces increasing pressure from rivals like Anthropic and gears up to file for an IPO later this year. In March, OpenAI’s CEO of AGI deployment, Fidji Simo, told staff that the company needs to simplify its product offerings. The push to divert resources to more consequential efforts resulted in OpenAI discontinuing its Sora video-generation app.

Unrelated to Weil’s news, two other executives announced on Friday that they are departing OpenAI. OpenAI’s chief technology officer of enterprise applications, Srinivas Narayanan, announced internally that he is leaving the company to spend time with his family. Narayanan had joined OpenAI as the company’s VP of engineering. And Bill Peebles, head of Sora, posted on X that he was done at OpenAI as well.

The exits of Weil, Peebles, and Narayanan are just the latest in a series of executive shake-ups at OpenAI. The company recently announced a major reorganization of its executive team as Simo took a medical leave to focus on her health. In the same announcement, OpenAI said cofounder and president Greg Brockman would oversee the company’s products in the interim, and the company’s chief marketing officer, Kate Rouch, would take a leave of absence due to medical issues. Chief operating officer Brad Lightcap transitioned to a “special projects” role as part of the restructuring as well.

Advertisement

OpenAI CEO Sam Altman seemed to acknowledge the various upheavals in a recent blog post. “I am also very aware that OpenAI is now a major platform, not a scrappy startup, and we need to operate in a more predictable way now,” he wrote. “It has been an extremely intense, chaotic, and high-pressure few years.”

Source link

Continue Reading

Tech

Nearly 75pc of AI’s economic value captured by just 20pc of companies

Published

on

PwC research found that Irish companies are somewhat lagging behind their global peers where AI implementation and benefits are concerned.

Professional services company PwC has released data exploring how organisational leaders are navigating AI gains across a range of areas, such as growth, revenue, investment, workflows, autonomous decisions, reinventing business models and governance, and analysing where the AI leaders are driving results.

PwC collected data for a survey from 1,217 senior executives around the world, including from Ireland, at a director level or above, at companies across 25 sectors and multiple regions worldwide. 

From that information, PwC found that nearly three-quarters (74pc) of AI’s economic gains are being utilised by only 20pc of companies. According to the findings, this is indicative of a “stark and widening divide between a small group of AI leaders and the majority of businesses still stuck in pilot mode”.

Advertisement

Commenting on the report, David Lee, the chief technology leader for PwC Ireland, said, “Many companies are busy rolling out AI pilots, but only a minority are converting that activity into measurable financial returns.

“The leaders stand out because they point AI at growth, not just cost reduction, and back that ambition with the foundations that make AI scalable and reliable.”

Is Ireland keeping pace?

Ireland specifically was found to be falling behind its global peers when it comes to AI implementation and benefits.

Lee said: “Based on our previous studies, Irish companies do somewhat lag global peers where AI implementation and benefits are concerned.”

Advertisement

He added that “PwC’s 2026 Irish CEO survey reveals fewer Irish CEOs (8pc) report AI application across a range of business areas compared to global counterparts (18pc), including demand generation, products, services, experiences and strategic direction-setting”.

He noted: “Some of the benefits from AI are also taking longer to come through compared to global peers, with Irish organisations seeing the opportunities from AI, but are not yet grasping the transformative powers.

“17pc of Irish CEOs say that AI has delivered increased revenues in the past 12 months, behind global peers (29pc). Nearly a quarter (23pc) say that AI has delivered cost reductions in the past 12 months, also behind global peers (26pc).”

The companies that are leading were found to be roughly two to three times more likely to use AI to identify and pursue growth opportunities or reinvent their business model. They are also twice as likely to redesign workflows to incorporate AI rather than simply adding new AI tools.

Advertisement

They are nearly three times more likely to have increased the number of decisions made without human intervention and were shown to be going further in relation to AI governance. Within high-performing companies, trust at scale models were found to be effective. 

The report said, “AI leaders are more likely than other companies to have mechanisms such as a responsible AI framework (1.7 times as likely as other companies) and a cross-functional AI governance board (1.5 times). As a result of their efforts, their employees are twice as likely to trust AI outputs.”

Time for a change

PwC’s report suggested that a failure to shift the current approach to the implementation of artificial intelligence by the majority would likely widen the performance gap between AI leaders and “laggards”, particularly as leading organisations continue to learn, grow, and automate safely and speedily.  

Commenting on the results of the research, Martin Duffy, the head of AI and emerging technologies at PwC Ireland, said: “AI return on investment comes down to execution discipline – clear metrics, fast stop-or-scale decisions and designs built for reuse. Value shows up when AI is embedded in everyday workflows, not isolated pilots.”

Advertisement

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement
Continue Reading

Tech

Weekend Apple Watch Series 11 deals deliver prices as low as $299

Published

on

Save $100 on numerous Apple Watch Series 11 styles this weekend, including aluminum and titanium options.

Two Apple Watch Series 11 models, one gold with white band and one silver with metal mesh band, with bold red Best Price label on dark geometric background
Grab an Apple Watch Series 11 from just $299 this weekend – Image credit: Apple

Amazon’s Apple Watch deals have ramped up for the second half of April, with the 42mm Series 11 returning to $299, the lowest price on record, for the weekend.
Buy Apple Watch S11 for $299
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Tech

Quordle hints and answers for Saturday, April 18 (game #1545)

Published

on

Looking for a different day?

A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Friday’s puzzle instead then click here: Quordle hints and answers for Friday, April 17 (game #1544).

Quordle was one of the original Wordle alternatives and is still going strong now more than 1,400 games later. It offers a genuine challenge, though, so read on if you need some Quordle hints today – or scroll down further for the answers.

Advertisement

Source link

Continue Reading

Tech

Amazon payments to Bezos’ Blue Origin reach $1.8B as shareholders cite conflicts of interest

Published

on

Jeff Bezos
Jeff Bezos, the billionaire founder of Amazon and Blue Origin, shows off a mockup of the New Shepard suborbital space capsule during a 2017 conference in Colorado. (GeekWire Photo / Kevin Lisota)

Amazon paid about $1.8 billion last year to Blue Origin, the space company owned by its founder and board chair Jeff Bezos — nearly triple the amount the year before — as the tech giant prepared to ramp up deployment of its own low-Earth orbit satellite constellation. 

The increase comes as shareholders weigh a proposal calling for a mandatory independent board chair, citing Bezos’ business interests outside Amazon as potential conflicts of interest. 

Bezos stepped down as Amazon’s CEO in 2021 but remains executive chairman.

According to the filing, the company paid approximately $2.2 billion total under satellite launch agreements during the past fiscal year, with an estimated $1.8 billion going to Blue Origin. The prior year’s proxy showed Blue Origin receiving about $578 million out of $1.7 billion total. 

Amazon is building a constellation of 3,236 low-Earth orbit satellites under the Amazon Leo program, formerly known as Project Kuiper, to beam broadband internet to consumers and businesses. The company has deployed 243 satellites so far and has asked the FCC for a two-year extension on a July deadline to launch roughly half of the fleet. 

Advertisement

The company this week also announced a $10.8 billion deal this week to acquire Globalstar, a satellite operator that has used SpaceX as its primary launch provider. 

Blue Origin’s New Glenn rocket made its debut flight in January 2025 but has not yet reached the launch cadence needed for the rollout. In addition to Blue Origin, Amazon has launch agreements in place with United Launch Alliance and Arianespace, and has also tapped Blue Origin rival SpaceX’s Falcon 9 for some launches, as Reuters reported this week

Bezos is also co-founder and co-CEO of AI startup Project Prometheus, a venture focused on applying AI to manufacturing and engineering across a variety of commercial sectors. 

The shareholder proposal calling for a mandatory independent chair, submitted by the AFL-CIO Reserve Fund, points to Bezos’ expanding role outside Amazon as cause for concern. 

Advertisement

“As a technology company, Project Prometheus could be a potential competitor or a business partner with our Company, raising potential conflicts of interest,” the proposal states, also citing Amazon’s multibillion-dollar launch agreements with Blue Origin as a potential conflict.

It notes that Amazon also has done business with the Bezos-owned Washington Post.

Amazon’s board recommends voting against the proposal, arguing that its lead independent director structure provides sufficient oversight. The role is currently held by Jamie Gorelick, a former U.S. Deputy Attorney General. The company’s annual meeting is set for May 20. 

The Blue Origin contracts have drawn scrutiny before. A shareholder lawsuit filed in 2023 alleged Amazon’s board spent less than 40 minutes approving the launch agreements without considering SpaceX as an alternative. Delaware’s Court of Chancery dismissed the case, and the state Supreme Court affirmed that ruling in November 2025.

Advertisement

Source link

Continue Reading

Tech

NYT Connections hints and answers for Saturday, April 18 (game #1042)

Published

on

Looking for a different day?

A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people are always playing ‘today’s game’ while others are playing ‘yesterday’s’. If you’re looking for Friday’s puzzle instead then click here: NYT Connections hints and answers for Friday, April 17 (game #1041).

Good morning! Let’s play Connections, the NYT’s clever word game that challenges you to group answers in various categories. It can be tough, so read on if you need Connections hints.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025