CurlyCOMrades Exploit Windows Hosts with Alpine Linux VMs

07 Nov 2025

Security researchers from Bitdefender and the Georgian CERT have exposed a new malware operation by CurlyCOMrades. They discovered that the hacker group deployed reverse-shell malware within Alpine Linux VMs on Windows hosts, targeting institutions in Georgia and Moldova since July 2025.

Exploitation Details

The attackers utilized the Hyper-V virtualization feature, disabling its management interface to conceal activities. They installed an Alpine Linux VM equipped with CurlyShell and CurlCat implants, along with PowerShell scripts, to facilitate unauthorized remote access and command execution.

The VM used the Hyper-V DefaultSwitch adapter, ensuring all VM traffic was routed through the host's network. This method masked the malicious activities as legitimate traffic, thereby bypassing endpoint detection response (EDR) systems on the host network.

Implications and Findings

The malware affected governmental and judicial bodies in Georgia and energy firms in Moldova. Though the exact victims remain unnamed, Bitdefender's investigation highlights the geopolitical motivations possibly aligning with Russian state interests, despite a lack of direct evidence linking them to the Russian government.

CurlyCOMrades, identified in 2024, continue to pose a significant threat through advanced network exploitation techniques, complicating detection efforts and raising surveillance needs in targeted regions.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6396952
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1275491
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495891
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453710
downloads

News and reviews for Desktop Windows

CurlyCOMrades Exploit Windows Hosts with Alpine Linux VMs

CurlyCOMrades hid malware in VMs on Windows to evade detection, affecting Georgia, Moldova.

Read more

Obsidian Focuses on Original IP Over New Fallout Game

Obsidian prioritizes original IP like The Outer Worlds 2, moving away from external franchises like Fallout.

Read more

FlyOOBE Bypass Tool Poses Security Risks for Windows 11 Users

FlyOOBE on Windows 11 can reduce security and expose users to malware risks. Caution advised.

Read more

Humble Choice Offers $256 in Steam Deck Games for $14.99

This month's Humble Choice features eight Steam Deck games worth $256 for a $14.99 subscription.

Read more

Ai.lien Horror Game Coming to PC in 2026

Tokyo-based developer unveils Ai.lien, a bishoujo horror visual novel for PC due in 2026, exploring human emotions via AI interactions.

Read more

Dead Static Drive Launches on Steam and Xbox Game Pass

Dead Static, a survival horror game set in 1980s Americana with Lovecraft influences, debuts on Steam and Xbox Game Pass today.

Read more

Oblivion Remastered Now 33% Off, Priced at $33.74

The Elder Scrolls IV: Oblivion Remastered, a UE5 update, is discounted 33%, enhancing graphics while preserving gameplay.

Read more

Curly COMrades Exploit Hyper-V for Security Bypasses

Curly COMrades use Microsoft Hyper-V to bypass security defenses and execute attacks. Identified in collaboration with the Georgian CERT.

Read more

Arc Raiders and Battlefield 6 Excel in Performance and Accessibility

Arc Raiders and Battlefield 6 attract players with strong performance, low system requirements. Gamer engagement sees boost in 2025.

Read more

Optimizing Arc Raiders: Best PC Settings for Performance

Boost Arc Raiders performance on PC with optimized settings for graphics and audio. Key changes include Nvidia configurations and frame rate tweaks.

Read more