CurlyCOMrades Exploit Windows Hosts with Alpine Linux VMs

07 Nov 2025

Security researchers from Bitdefender and the Georgian CERT have exposed a new malware operation by CurlyCOMrades. They discovered that the hacker group deployed reverse-shell malware within Alpine Linux VMs on Windows hosts, targeting institutions in Georgia and Moldova since July 2025.

Exploitation Details

The attackers utilized the Hyper-V virtualization feature, disabling its management interface to conceal activities. They installed an Alpine Linux VM equipped with CurlyShell and CurlCat implants, along with PowerShell scripts, to facilitate unauthorized remote access and command execution.

The VM used the Hyper-V DefaultSwitch adapter, ensuring all VM traffic was routed through the host's network. This method masked the malicious activities as legitimate traffic, thereby bypassing endpoint detection response (EDR) systems on the host network.

Implications and Findings

The malware affected governmental and judicial bodies in Georgia and energy firms in Moldova. Though the exact victims remain unnamed, Bitdefender's investigation highlights the geopolitical motivations possibly aligning with Russian state interests, despite a lack of direct evidence linking them to the Russian government.

CurlyCOMrades, identified in 2024, continue to pose a significant threat through advanced network exploitation techniques, complicating detection efforts and raising surveillance needs in targeted regions.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508625
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735676
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746785
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
497048
downloads

Comments (0)

No comments yet. Be the first to comment!