Curly COMrades
Curly COMrades is a previously undocumented cyber-espionage threat actor tracked by Bitdefender since mid-2024 and assessed to operate in support of Russian geopolitical interests. Bitdefender reported insufficient evidence to attribute the activity to an existing known group, although Amazon noted overlap between a Russian-nexus cluster, Sandworm, and an actor Bitdefender tracks as Curly COMrades. Reported targets include judicial and government bodies in Georgia and an energy distribution company or energy firms in Moldova. The actor’s objective is long-term covert access, credential theft, lateral movement, and data exfiltration. Observed credential-access activity includes repeated attempts to extract NTDS.dit, LSASS dumping, and DCSync, using tooling and methods including Mimikatz, comsvcs.dll abuse, procdump, Volume Shadow Copy NTDS extraction, and custom or adapted LSASS dump tools. The group also used common discovery commands and Active Directory PowerShell cmdlets. Curly COMrades relies heavily on proxying, tunneling, and remote access tooling, including Resocks, SOCKS5 servers, SSH remote port forwarding, Stunnel, Ligolo-ng, Rsockstun, CCProxy, and the legitimate RMM tool Remote Utilities (RuRat). The actor also used compromised legitimate websites as relays for command-and-control and exfiltration to blend with normal traffic. Exfiltration was described as relatively infrequent and often manually driven, with data commonly staged in C:\Users\Public\Documents, archived with rar.exe, and uploaded with curl.exe. Bitdefender identified a custom three-stage .NET backdoor named MucorAgent. MucorAgent uses COM/CLSID hijacking for persistence tied to .NET NGEN scheduled task execution under SYSTEM, including observed hijacking of CLSIDs {de434264-8fe9-4c0b-a83b-89ebeebff78e} and {613fba38-a3df-4ab8-9674-5604984a299a}. It executes AES-encrypted PowerShell through the System.Management.Automation namespace without launching powershell.exe, applies an AMSI bypass, and exfiltrates results via curl.exe while disguising output as PNG data. A notable tradecraft element is abuse of Microsoft Hyper-V on compromised Windows 10 systems to create a hidden Alpine Linux-based virtual machine for stealthy operations and EDR evasion. The attackers enabled Hyper-V, disabled the Hyper-V management clients feature, imported a lightweight VM disguised as "WSL," and used Hyper-V’s Default Switch so outbound traffic appeared to originate from the host IP. Inside the VM they deployed two custom implants: CurlyShell, a persistent HTTPS reverse shell with cron-based persistence, and CurlCat, a reverse proxy/tunneling tool that wraps SSH traffic in HTTP/HTTPS requests. Bitdefender and the Georgian CERT also reported PowerShell-based post-exploitation including Kerberos ticket injection into LSASS and Group Policy-distributed scripts that created or reset local accounts for persistence. Known aliases and related names directly mentioned in the content are limited to Curly COMrades / curly_comrades. Custom malware and subcomponents associated with the actor include MucorAgent, CurlyShell, and CurlCat.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- government
- energy
Tradecraft
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage actor targeting Georgia and Moldova; attempts to extract NTDS from domain controllers; uses NGEN COM hijacking and other stealth techniques for long-term access.
Referenced as an overlapping activity cluster with the GRU-linked campaign; associated with targeting edge devices and (earlier) exploitation of WatchGuard/Confluence/Veeam vulnerabilities, shifting in 2025 toward sustained targeting of misconfigured network edge devices and credential replay patterns.
Alleged Russian operation maintaining covert, long-term access by abusing Windows Hyper-V to run a hidden VM-based operating environment for persistence/evasion on compromised endpoints.
Curly COMrades is a Russian-backed threat actor group known for using innovative evasion and persistence techniques, such as hiding malware in Hyper-V virtual machines, to avoid detection and maintain access to compromised systems.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.