Categories: Cyber Security News

Curly COMrades’ Latest Toolset Installs Undetected Remote Access on Windows 10 Systems

A joint investigation by Bitdefender Labs and the Georgian CERT (CERT.OTA.GOV.GE) has revealed a sophisticated new campaign by the Curly COMrades threat actor, a group operating in support of Russian geopolitical interests.

The latest findings describe how the attackers leveraged Microsoft’s Hyper-V virtualization to create covert, fully isolated environments that allowed stealthy remote access and command execution on compromised Windows 10 hosts.

Instead of deploying traditional malware directly on the host, the attackers enabled the Hyper-V feature remotely and imported a lightweight Alpine Linux virtual machine specially crafted for stealth and persistence.

This VM, occupying just 120MB of disk space and 256MB of memory, served as an invisible operational base. Inside it, two custom implants named CurlyShell and CurlCat were discovered, both written in C++ and built using the libcurl library.

CurlyShell established a persistent HTTPS-based reverse shell, while CurlCat managed SSH tunneling, allowing attackers to pivot within victim networks unseen.

By isolating these tools within the VM, Curly COMrades bypassed endpoint detection and response (EDR) systems, which typically monitor host processes rather than virtualized environments.

CurlyShell and CurlCat: Custom Malware in a Virtual Cage

The decompiled binaries show near-identical codebases for both implants. CurlyShell executed attacker commands using a non-standard Base64 encoding scheme, while CurlCat relayed SSH data over HTTP to blend with legitimate web traffic.

Their minimalist design reduced forensic traces, demonstrating an evolved operational discipline. The VM’s network adapter, set to the Default Switch in Hyper-V, routed malicious traffic through the host’s network stack using internal NAT.

This ensured all C2 communications appeared to originate from the legitimate IP of the infected machine. Evidence within the VM custom DNS entries and domain mapping files confirmed domain-specific tailoring for each target environment.

Curly comrades remote access windows 10

Additional PowerShell scripts expanded the threat actor’s toolkit, including one abusing Kerberos tickets for remote authentication and another distributed via Group Policy to maintain persistence through local account creation and password resets.

Advanced Evasion Tactics and Industry Collaboration

The operation’s discovery stemmed from Georgian CERT analysts detecting CurlCat traffic linked to a compromised domestic website acting as a C2 relay.

Joint forensic analysis uncovered NGINX and iptables configurations that rerouted victim connections to external servers, confirming the group’s infrastructure setup and strong operational security.

The decompiled view shows similarities between CurlCat (left) and CurlyShell (right) code.

Bitdefender emphasized that this campaign signals a growing trend: threat actors increasingly abusing legitimate virtualization frameworks to evade EDR and XDR detection.

Experts recommend adopting multilayered defenses such as network-level monitoring, attack surface reduction, and proactive hardening to detect traffic escaping from virtualized malware environments before it reaches its command‑and‑control endpoint.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post Curly COMrades’ Latest Toolset Installs Undetected Remote Access on Windows 10 Systems appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Justice for the Quakertown 5 Movement Continues to Demand Transparency and Police Accountability

Concerns over allegations of excessive police force on February 20 when a Quakertown high school…

10 minutes ago

Student-directed play showcased in youth mental health event

Less than an hour before showtime, eight Concord High School girls helped put tiny braids…

30 minutes ago

Report gives snapshot of food access challenges, insecurity in Kearsarge region

The rural character of the Kearsarge region defines almost every dimension of food access for…

30 minutes ago

More bears means new rules in Pemi Wilderness

If you’re planning an overnight trip to the Pemigewasset Wilderness, add one thing to your…

30 minutes ago

Alien: Isolation 2 Seemingly Teased in New Video Posted by Sega and Creative Assembly

Publisher Sega and developer Creative Assembly have revealed what appears to be a teaser trailer…

3 hours ago

Trump Uses Shooting Outside White House Correspondents’ Dinner to Boost Corrupt Ballroom Project

US President Donald Trump used a lone gunman’s storming of the lobby outside the White House Correspondents’ Dinner on…

3 hours ago

This website uses cookies.