Frequency
5
occurrences
First Seen
December 4, 2025
Last Seen
April 17, 2026
Related Threat Clusters
-
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
Matanbuchus 3.0 Malware Analysis: New Features and Ransomware Links
Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis…
2 articles · Updated December 4, 2025 -
Vishing Attack Uses Microsoft Teams and QuickAssist to Spread .NET Malware
A new vishing attack has been identified that exploits Microsoft Teams and QuickAssist to deploy .NET malware. This attack targets users through social engineering tactics, potentially affecting organizations that…
3 articles · Updated December 9, 2025
Recent Intelligence Reports
- Payouts King ransomware uses QEMU VMs to bypass endpoint security — Bleepingcomputer · April 17, 2026
- Microsoft Teams and QuickAssist Exploited in New Vishing Attack to Spread .NET Malware — Cyberpress · December 9, 2025
- New Vishing Attack Leverages Microsoft Teams Call and QuickAssist to Deploy .NET Malware — Cybersecuritynews · December 9, 2025
- New Vishing Attack Exploits Microsoft Teams and QuickAssist to Deploy .NET Malware — Gbhackers · December 9, 2025
- Matanbuchus 3.0 Malware: Technical Analysis — Socprime · December 4, 2025