Bleepingcomputer
Curly COMrades Exploit Hyper-V for Covert Malware Operations
Article Content
The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain persistent access. Their operations include deploying custom malware tools such as the CurlyShell reverse shell and CurlCat reverse proxy. This activity has been linked to cyber-espionage efforts supported by Russian interests since mid-2024.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.