CurlyCOMrades Exploit Windows Hosts with Alpine Linux VMs

07 Nov 2025

Security researchers from Bitdefender and the Georgian CERT have exposed a new malware operation by CurlyCOMrades. They discovered that the hacker group deployed reverse-shell malware within Alpine Linux VMs on Windows hosts, targeting institutions in Georgia and Moldova since July 2025.

Exploitation Details

The attackers utilized the Hyper-V virtualization feature, disabling its management interface to conceal activities. They installed an Alpine Linux VM equipped with CurlyShell and CurlCat implants, along with PowerShell scripts, to facilitate unauthorized remote access and command execution.

The VM used the Hyper-V DefaultSwitch adapter, ensuring all VM traffic was routed through the host's network. This method masked the malicious activities as legitimate traffic, thereby bypassing endpoint detection response (EDR) systems on the host network.

Implications and Findings

The malware affected governmental and judicial bodies in Georgia and energy firms in Moldova. Though the exact victims remain unnamed, Bitdefender's investigation highlights the geopolitical motivations possibly aligning with Russian state interests, despite a lack of direct evidence linking them to the Russian government.

CurlyCOMrades, identified in 2024, continue to pose a significant threat through advanced network exploitation techniques, complicating detection efforts and raising surveillance needs in targeted regions.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6398330
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276326
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495973
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453727
downloads

News and reviews for Desktop Windows

Adds Baldur's Gate to Xbox Game Pass for PC

Baldur's Gate and its Enhanced sequel debut on Xbox Game Pass for PC today, despite an earlier delay. Expect enriched visuals and lengthy gameplay.

Read more

Curly COMrades Leverage Hyper-V for Stealthy Operations

Curly COMrades exploits Hyper-V on Windows for covert VM-based attacks, evading EDR detection.

Read more

Frontier Develops Planet Zoo Sequel for Future Release

Frontier Developments announces it is creating a sequel to Planet Zoo. Expected developments are to be revealed in 2026, delighting simulation fans.

Read more

Steam's Movember Bundle Offers $350 Games for $20

The Movember bundle by Fanatical offers $350 in Steam games for $20 this month, featuring prominent titles like Chivalry 2 and Gloomwood.

Read more

Paradox Enhances EU5 Performance Amid Initial Issues

Paradox Tinto tackles EU5 performance inconsistencies, offering fixes and optimizations to improve gameplay experience.

Read more

Hackers Use Linux Malware to Evade Windows Security

Attackers employ Linux malware on Windows for stealth, compromising security via Hyper-V.

Read more

Game Pass Drives Massive Play but Low Revenue for ‘Savage Planet’

Revenge of the Savage Planet sees high Game Pass player numbers, but revenue disappoints, says Creative Director Alex Hutchinson.

Read more

Launch Solasta 2 in Early Access Q1 2026

Solasta 2 enters early access in Q1 2026 with new features, expanding gameplay options for fans.

Read more

CurlyCOMrades Exploit Windows Hosts with Alpine Linux VMs

CurlyCOMrades hid malware in VMs on Windows to evade detection, affecting Georgia, Moldova.

Read more

Obsidian Focuses on Original IP Over New Fallout Game

Obsidian prioritizes original IP like The Outer Worlds 2, moving away from external franchises like Fallout.

Read more