CurlCat Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 4, 2025
Last Seen
November 5, 2025

Related Threat Clusters

  • Curly COMrades Exploit Hyper-V for Covert Cyberespionage

    The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…

    1 article · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…

    4 articles · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…

    5 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Russian APT abuses Windows Hyper — Csoonline · November 5, 2025
  • Russian spies pack custom malware into hidden VMs on Windows machines — Theregister · November 4, 2025
  • Curly COMrades: Evasion and Persistence via Hidden Hyper — Bitdefender · November 4, 2025
  • Russian hackers abuse Hyper — Bleepingcomputer · November 4, 2025

CVSS v3.1 Breakdown