Curly COMrades
0 incidentes
0 paises
0 sectores
apt Russia Ultimo: -
Curly COMrades is a Russian-speaking threat actor group that emerged in late 2023, operating in support of Russian geopolitical interests. The group primarily focuses on cyber espionage, credential theft, and maintaining long-term access to target networks, particularly in Eastern Europe. What distinguishes Curly COMrades is their innovative use of Hyper-V virtualization to hide Linux-based virtual machines containing custom malware, thereby evading traditional endpoint detection and response tools. Additionally, they employ a unique persistence mechanism involving Component Object Model (COM) hijacking to leverage Microsoft's Native Image Generator (NGEN). The group's name itself reflects their heavy reliance on the curl.exe utility for command-and-control communications and their use of COM object hijacking.