Uptime Hamster: 11d 18h 48mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Curly COMrades

Curly COMrades

0 incidentes 0 paises 0 sectores apt Russia Ultimo: -
Ver en IntelTracker → APTTrail →
Curly COMrades is a Russian-speaking threat actor group that emerged in late 2023, operating in support of Russian geopolitical interests. The group primarily focuses on cyber espionage, credential theft, and maintaining long-term access to target networks, particularly in Eastern Europe. What distinguishes Curly COMrades is their innovative use of Hyper-V virtualization to hide Linux-based virtual machines containing custom malware, thereby evading traditional endpoint detection and response tools. Additionally, they employ a unique persistence mechanism involving Component Object Model (COM) hijacking to leverage Microsoft's Native Image Generator (NGEN). The group's name itself reflects their heavy reliance on the curl.exe utility for command-and-control communications and their use of COM object hijacking.
Tecnicas MITRE
T1090 - Proxy, T1133 - External Remote Services, T1212 - Exploitation for Credential Access, T1059.001 - PowerShell, T1021 - Remote Services, T1069.002 - Domain Groups
CVEs relacionadas
CVE-2025-62626, CVE-2025-23358, CVE-2025-20358, CVE-2025-20354, CVE-2025-12779, CVE-2023-27532
Tipo
apt
Pais origen
Russia
Motivacion
-
Impacto
39
Actualizado
Mon, 13 Ap