Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection
It has been noted that the threat actor Curly COMrades uses virtualization technology to get around security measures and run bespoke malware.
A recent Bitdefender report claims that the adversary enabled the Hyper-V role on a few victim systems in order to set up a simple virtual machine running Alpine Linux.
According to a technical report by security researcher Victor Vrabie, Adrian Schipor, and Martin Zugec, this hidden environment hosted their custom reverse shell, CurlyShell, and a reverse proxy, CurlCat, with a small footprint (just 120MB disk space and 256MB memory).
Curly COMrades was initially documented by the Romanian cybersecurity provider in August 2025 in relation with a series of attacks targeting Georgia and Moldova read more about Hackers Weaponize Windows Hyper...

