News

Payouts King ransomware uses QEMU VMs to bypass endpoint security

  • Bill Toulas--BleepingComputer
  • published date: 2026-04-17 19:10:19 UTC

The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. [...]

The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. QEMU is an open-source CPU emulat… [+4667 chars]