CurlyShell is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity November 5, 2025.
CurlyShell is a malware family linked to Russian APT activity that uses virtualization-based techniques to hide components and maintain persistence on Windows hosts. Analyses reference evasion via 'Hidden Hyper' and the use of hidden virtual machines (VMs) to host payloads, enabling covert execution and resilience against security tooling. This hypervisor-level stealth marks a significant evolution in state-sponsored malware tradecraft.
The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…
The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…
The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…