It has been noted that the threat actor Curly COMrades uses virtualization technology to get around security measures and run bespoke malware.
A recent Bitdefender report claims that the adversary enabled the Hyper-V role on a few victim systems in order to set up a simple virtual machine running Alpine Linux.
According to a technical report by security researcher Victor Vrabie, Adrian Schipor, and Martin Zugec, this hidden environment hosted their custom reverse shell, CurlyShell, and a reverse proxy, CurlCat, with a small footprint (just 120MB disk space and 256MB memory).
Curly COMrades was initially documented by the Romanian cybersecurity provider in August 2025 in relation with a series of attacks targeting Georgia and Moldova read more about Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
