CurlyShell Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 4, 2025
Last Seen
November 5, 2025

CurlyShell is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity November 5, 2025.

Overview

CurlyShell is a malware family linked to Russian APT activity that uses virtualization-based techniques to hide components and maintain persistence on Windows hosts. Analyses reference evasion via 'Hidden Hyper' and the use of hidden virtual machines (VMs) to host payloads, enabling covert execution and resilience against security tooling. This hypervisor-level stealth marks a significant evolution in state-sponsored malware tradecraft.

Related Threat Clusters

  • Curly COMrades Exploit Hyper-V for Covert Cyberespionage

    The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…

    1 article · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…

    4 articles · Updated November 5, 2025
  • Curly COMrades Exploit Hyper-V for Covert Malware Operations

    The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…

    5 articles · Updated November 5, 2025

Recent Intelligence Reports

  • Russian APT abuses Windows Hyper — Csoonline · November 5, 2025
  • Russian spies pack custom malware into hidden VMs on Windows machines — Theregister · November 4, 2025
  • Curly COMrades: Evasion and Persistence via Hidden Hyper — Bitdefender · November 4, 2025
  • Russian hackers abuse Hyper — Bleepingcomputer · November 4, 2025

CVSS v3.1 Breakdown