Curly COMrades Leverage Hyper-V for Stealthy Operations

07 Nov 2025

The cyberespionage group Curly COMrades has leveraged Windows Hyper-V to execute stealthy malware operations. Researchers from Bitdefender have reported that this group deploys Linux-based virtual machines (VMs) on compromised Windows 10 systems to hide malicious activities.

Windows Hyper-V Exploitation

Curly COMrades use the Hyper-V role on victim systems to launch a lightweight Alpine Linux VM, which houses custom implants like CurlyShell and CurlCat. These implants, built with libcurl, facilitate malicious operations such as reverse shell access and SSH tunneling.

  • Curly COMrades leverage Windows Hyper-V to deploy minimalistic 120 MB Alpine Linux VMs.
  • The attackers use the DISM tool to enable Hyper-V while disabling its graphical interface.
  • Pre-built Alpine Linux VM images are imported using PowerShell cmdlets.

Security Evasion Techniques

By isolating malware within VMs, the group effectively bypasses traditional host-based Endpoint Detection and Response (EDR) systems. This tactic allows them to execute commands covertly and evade detection more effectively. Bitdefender emphasizes the need for enhanced host-based network inspection strategies to counter such sophisticated threats. Organizations are advised to employ proactive hardening to reduce the risk of exploiting native system binaries.

Implications for Cyber Defense

This campaign signals a shift in threat tactics as adversaries seek new ways to circumvent increasingly robust EDR solutions. The use of virtual machines for malware operations highlights the necessity for defense-in-depth strategies. Organizations should strive to create environments that are inhospitable to attackers, incorporating multilayered defenses to bolster security measures.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7154891
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1601305
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
686745
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
483935
downloads

News and reviews for Desktop Windows

Registry Tweak Unlocks NVMe Driver on Consumer PCs

A Windows Registry tweak enables NVMe driver use on consumer PCs, boosting SSD speed but risking system stability.

Read more

Top 2026 PC Games to Watch: Nova Roma to GTA 6

Explore anticipated 2026 PC games like Nova Roma and GTA 6. Discover release plans and potential impact on gaming.

Read more

Windows 10 Users Access Extended Security Updates Until 2026

Windows 10 users can get security updates through 2026 via Microsoft's ESU program, aiding security during the transition to new platforms.

Read more

Windows Installer Cleanup: Safely Free Up Disk Space

Learn how to manage the C:\Windows\Installer cache. Safely free disk space without breaking updates or repairs.

Read more

Top PC Games to Watch in 2026: Key Releases and Changes

Explore the most anticipated PC games for 2026 featuring unique strategies and innovative design shifts.

Read more

Optimization Review: 2025's Worst-Performing PC Games

How optimization issues impacted 2025's PC game releases, with many titles facing major performance challenges.

Read more

AI Games: Developer Skeptical of AI-Led Creation

Adrian Chmielarz doubts AI games as feasible soon due to hardware limits and creative needs.

Read more

CD Projekt Sells GOG to Co-Founder for $25.2M

CD Projekt sells GOG back to co-founder Michal Kicinski for $25.2M to refocus on game development.

Read more

Microsoft Embeds AI Agents in Windows for Major 2025 Update

Microsoft to integrate AI agents into Windows by 2025, enhancing task management and AI ecosystem.

Read more

pingPong Launches: AIM-Style Chat App with Retro Appeal

A 15-year-old's pingPong app channels retro AIM style, merging nostalgia with modern devices.

Read more