Hackers Use Linux Malware to Evade Windows Security

07 Nov 2025

Hackers have increasingly utilized Linux malware to bypass Windows security, causing significant challenges for endpoint detection and response (EDR) systems.

Exploit Details and Tools

Bitdefender and Georgia CERT uncovered a Russian hacker group, Curly COMrades, exploiting Hyper-V on Windows 10. They used lightweight Alpine Linux VMs to evade detection, employing tools like Resocks, Ligolo-ng, and SSH-based methods for persistence and proxying. The attack began in July 2024 with DISM commands and disabled management interfaces to conceal remote VM operations.

Impact on Security Practices

This campaign emphasizes the need for enhanced EDR with host-based network monitoring to identify C2 traffic from VMs. Security measures must evolve to detect such Linux-based threats on Windows platforms, as these tactics are becoming more prevalent.

Advanced Techniques Used

CurlyShell and CurlCat, two custom programs, were deployed: CurlyShell acts as a reverse shell, and CurlCat manages traffic tunnels, profoundly impacting remote access capabilities. The threat actors also leveraged default network adapters and Hyper-V's internal NAT, masking malicious traffic as legitimate host traffic to bypass security systems.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6414150
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1283575
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496907
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454083
downloads

News and reviews for Desktop Windows

Misery Delisted from Steam After DMCA Complaint

Misery removed from Steam after DMCA by GSC Game World. Developer disputes claims, plans response.

Read more

Announce Elden Ring: Nightreign DLC for FY2025 Release

FromSoftware plans to release Elden Ring: Nightreign DLC in FY2025, expanding on the Elden Ring universe.

Read more

Free Windows 10 Security Updates Require Enrollment

Windows 10 users must enroll in Extended Security Updates by 2025-11-08 to maintain protection.

Read more

Flyoobe Compromised: Caution Advised for Windows 10 Users

Flyoobe, a Windows 11 bypass tool, faces malware threats through fake versions, urging users to download only from the official GitHub.

Read more

Fake Flyoobe Tool Targets Windows 10 Users

Fraudsters are distributing a fake Flyoobe tool for Windows 11 installs, posing security risks.

Read more

Skopje '83 Demo Update Adds Performance Boost and Content

Indie studio Dark-1 releases updated demo for Skopje '83; new content, better performance. Early Steam discount until 2023-11-14.

Read more

NetEase Ends Partnership with Jackalyptic Games

NetEase has ended its collaboration with Jackalyptic Games, impacting the Warhammer MMO project and studio employees now seeking new positions.

Read more

Arc Raiders Exceeds Battlefield 6 in Steam Player Count

Arc Raiders draws large audience on Steam, surpassing Battlefield 6's peak players. Impact: increased accessibility in extraction shooter genre.

Read more

Nightingale November Update Enhances Gameplay with New Charms

The November 2025 Nightingale update adds charms, weapon buffs, and magic rebalances, promising a richer gaming experience.

Read more

Elestrals Awakened Hits Kickstarter Milestone with 2027 PC Release

Elestrals Awakened, a retro JRPG, breaks records on Kickstarter, set for PC release in 2027.

Read more