Curly COMrades Leverage Hyper-V for Stealthy Operations

07 Nov 2025

The cyberespionage group Curly COMrades has leveraged Windows Hyper-V to execute stealthy malware operations. Researchers from Bitdefender have reported that this group deploys Linux-based virtual machines (VMs) on compromised Windows 10 systems to hide malicious activities.

Windows Hyper-V Exploitation

Curly COMrades use the Hyper-V role on victim systems to launch a lightweight Alpine Linux VM, which houses custom implants like CurlyShell and CurlCat. These implants, built with libcurl, facilitate malicious operations such as reverse shell access and SSH tunneling.

  • Curly COMrades leverage Windows Hyper-V to deploy minimalistic 120 MB Alpine Linux VMs.
  • The attackers use the DISM tool to enable Hyper-V while disabling its graphical interface.
  • Pre-built Alpine Linux VM images are imported using PowerShell cmdlets.

Security Evasion Techniques

By isolating malware within VMs, the group effectively bypasses traditional host-based Endpoint Detection and Response (EDR) systems. This tactic allows them to execute commands covertly and evade detection more effectively. Bitdefender emphasizes the need for enhanced host-based network inspection strategies to counter such sophisticated threats. Organizations are advised to employ proactive hardening to reduce the risk of exploiting native system binaries.

Implications for Cyber Defense

This campaign signals a shift in threat tactics as adversaries seek new ways to circumvent increasingly robust EDR solutions. The use of virtual machines for malware operations highlights the necessity for defense-in-depth strategies. Organizations should strive to create environments that are inhospitable to attackers, incorporating multilayered defenses to bolster security measures.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6403227
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1278423
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496208
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453854
downloads

News and reviews for Desktop Windows

ES-DE Update 3.4.0 Enhances Gaming Features

ES-DE 3.4.0 introduces PlayStation 3, Steam, and Epic Games Store support, enhancing game tracking.

Read more

Halo Infinite Enters Maintenance Mode

Halo Infinite halts major updates with Operation: Infinite finalizing content changes as Halo Studios shifts focus.

Read more

Frostpunk 2 Drops to Lowest Price Before DLC Launch

Frostpunk 2 reached its lowest price, $23.39, ahead of the Fractured Utopias DLC release, impacting city-building strategy fans.

Read more

Launches Battleplan: New Strategy Game Battles in WW2

Battleplan, a new WW2 strategy by Slitherine, promises realism in month-long battles. Players can command vast troops and plan tactics daily.

Read more

Mafia: The Old Country Exceeds Sales Expectations

Take-Two's Mafia: The Old Country surpasses sales goals after offering a concise narrative. Developed by Hangar 13, the game finds unexpected success.

Read more

Steam Sees Indie Game Surge Driven by Small Hits

Steam enters a 'golden age' of indie games, driven by small, fast-produced hits, impacting developers and trends.

Read more

Hollow Knight Silksong Patch 4 Enhances Gameplay Features

Silksong's Patch 4 brings gameplay improvements and localization updates from Team Cherry, boosting features and fixing bugs.

Read more

Kingdom Come: Deliverance 2 Free to Play Until 2023-11-10

Kingdom Come: Deliverance 2 is free to play until 2023-11-10. Explore Mysteria Ecclesiae DLC soon. A limited-time discount is available.

Read more

Battlestar Galactica Deadlock Delisting on 2025-11-15

Battlestar Galactica Deadlock, a strategy game by Black Lab Games, faces delisting on all platforms starting 2025-11-15. Existing players remain unaffected.

Read more

Windows 11 Update May Streamline Context Menu

Microsoft revealed a new 'Split ContextMenu' feature for WinUI 3 apps, hinting at potential context menu improvements in Windows 11.

Read more