Jump to content
  • Russian hackers hit Windows machines via Linux VMs with new custom malware

    aum

    • 324 views
    • 3 minutes
     Share


    • 324 views
    • 3 minutes

    Hiding malware in VMs bypasses security protections

     

    •     Curly COMrades deployed Alpine Linux VMs on Windows hosts to hide reverse-shell malware activity
    •     VM traffic tunneled via host IP, bypassing traditional EDR and masking outbound communications
    •     Targets included Georgian and Moldovan institutions; operations align with Russian geopolitical interests

     

    Russian hackers known as Curly COMrades have been seen hiding their malware in Linux-based virtual machines (VM) deployed on Windows devices, experts have warned.

     

    Security researchers from Bitdefender after analyzing the latest activities together with the Georgian Computer Emergency Response Team (CERT), found Curly COMrades first started targeting their victims in July 2025, when they ran remote commands to enable the microsoft-hyper-v virtualization feature and disable its management interface.

     

    Then, they used the feature to download a lightweight Alpine Linux-based VM containing multiple malware implants.

     

    Russian attackers

     

    The malware deployed in this campaign is called CurlyShell and CurlCat, both of which provide a reverse shell. The hackers also deployed PowerShell scripts which granted remote authentication and arbitrary command execution capabilities.

     

    To hide the activity in plain sight, they configured the VM to use the Default Switch network adapter in Hyper-V. That way, all of the VM’s traffic went through the host’s network stack using Hyper-V’s internal network.

     

    "In effect, all malicious outbound communication appears to originate from the legitimate host machine's IP address," the researchers explained. "By isolating the malware and its execution environment within a VM, the attackers effectively bypassed many traditional host-based EDR detections."

     

    Curly COMrades were first spotted in 2024 and while their activities align with the interests of the Russian Federation, a direct link was not found. In August 2025, Bitdefender reported that their victims included government and judicial organizations in Georgia, and energy companies in Moldova. The victims in this incident were not named.

     

    Bitdefender stressed that there are no strong overlaps with known Russian APT groups, but Curly COMrades’ operations “align with the geopolitical goals of the Russian Federation."

     

    Ever since Russia’s attention turned towards Ukraine in 2014 with the annexation of Crimea, countries on its eastern border have lost the spotlight. Georgia, however, is in a similar position to Ukraine, with two regions declaring independence with the help of the Russian military - South Ossetia, and Abkhazia. Therefore, it would make sense that Russia’s cyberspies would like to keep tabs on neighboring countries and their diplomatic efforts.

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...