Curly COMrades Leverage Hyper-V for Stealthy Operations

07 Nov 2025

The cyberespionage group Curly COMrades has leveraged Windows Hyper-V to execute stealthy malware operations. Researchers from Bitdefender have reported that this group deploys Linux-based virtual machines (VMs) on compromised Windows 10 systems to hide malicious activities.

Windows Hyper-V Exploitation

Curly COMrades use the Hyper-V role on victim systems to launch a lightweight Alpine Linux VM, which houses custom implants like CurlyShell and CurlCat. These implants, built with libcurl, facilitate malicious operations such as reverse shell access and SSH tunneling.

  • Curly COMrades leverage Windows Hyper-V to deploy minimalistic 120 MB Alpine Linux VMs.
  • The attackers use the DISM tool to enable Hyper-V while disabling its graphical interface.
  • Pre-built Alpine Linux VM images are imported using PowerShell cmdlets.

Security Evasion Techniques

By isolating malware within VMs, the group effectively bypasses traditional host-based Endpoint Detection and Response (EDR) systems. This tactic allows them to execute commands covertly and evade detection more effectively. Bitdefender emphasizes the need for enhanced host-based network inspection strategies to counter such sophisticated threats. Organizations are advised to employ proactive hardening to reduce the risk of exploiting native system binaries.

Implications for Cyber Defense

This campaign signals a shift in threat tactics as adversaries seek new ways to circumvent increasingly robust EDR solutions. The use of virtual machines for malware operations highlights the necessity for defense-in-depth strategies. Organizations should strive to create environments that are inhospitable to attackers, incorporating multilayered defenses to bolster security measures.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6398462
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276364
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495985
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453730
downloads

News and reviews for Desktop Windows

PC Gamer Features Heroes of Might and Magic: Olden Era

PC Gamer exclusively reveals Heroes of Might and Magic: Olden Era. Developer Unfrozen revives this classic series, blending nostalgia with modern elements.

Read more

EndClientRAT Bypasses Security Using Stolen Code Signing

EndClientRAT uses compromised code-signing in a campaign against North Korean rights defenders. Antivirus evasion and targeted attacks detailed.

Read more

Adds Baldur's Gate to Xbox Game Pass for PC

Baldur's Gate and its Enhanced sequel debut on Xbox Game Pass for PC today, despite an earlier delay. Expect enriched visuals and lengthy gameplay.

Read more

Curly COMrades Leverage Hyper-V for Stealthy Operations

Curly COMrades exploits Hyper-V on Windows for covert VM-based attacks, evading EDR detection.

Read more

Frontier Develops Planet Zoo Sequel for Future Release

Frontier Developments announces it is creating a sequel to Planet Zoo. Expected developments are to be revealed in 2026, delighting simulation fans.

Read more

Steam's Movember Bundle Offers $350 Games for $20

The Movember bundle by Fanatical offers $350 in Steam games for $20 this month, featuring prominent titles like Chivalry 2 and Gloomwood.

Read more

Paradox Enhances EU5 Performance Amid Initial Issues

Paradox Tinto tackles EU5 performance inconsistencies, offering fixes and optimizations to improve gameplay experience.

Read more

Hackers Use Linux Malware to Evade Windows Security

Attackers employ Linux malware on Windows for stealth, compromising security via Hyper-V.

Read more

Game Pass Drives Massive Play but Low Revenue for ‘Savage Planet’

Revenge of the Savage Planet sees high Game Pass player numbers, but revenue disappoints, says Creative Director Alex Hutchinson.

Read more

Launch Solasta 2 in Early Access Q1 2026

Solasta 2 enters early access in Q1 2026 with new features, expanding gameplay options for fans.

Read more