Hyper-V Exploited for Covert Linux Malware on Windows Systems

07 Nov 2025

Curly COMrades, a Russian-linked APT group, has been found using Microsoft's Hyper-V to deploy hidden Alpine Linux virtual machines on compromised Windows systems, avoiding detection. Discovered in mid-2025, the operation isolates malware from host-based detection tools, maintaining covert access.

Operational Techniques

The attackers remotely enabled the Hyper-V role on targeted Windows machines and disabled its management interface. They used PowerShell to import a compressed VM image disguised as a video file. The VM environment, named “WSL”, runs Alpine Linux with a 120MB disk and 256MB RAM, leveraging Hyper-V's Default Switch for network traffic obfuscation.

  • Curly COMrades utilized native Windows virtualization for stealth attack.
  • Alpine Linux VM image was deployed using PowerShell scripts.
  • Hyper-V Default Switch masked VM traffic as originating from the Windows host.

Malware Components

Two ELF implants were introduced within the VM: CurlyShell and CurlCat. CurlyShell offers a persistent reverse shell using HTTPS for command and control, maintaining persistence with a root cron job. CurlCat functions as a reverse proxy, embedding SSH within HTTP requests, with RSA authentication keys for security.

Beyond the VM, PowerShell scripts enabled remote execution and lateral movement via encrypted Kerberos tickets. Persistence relied on GPO-distributed scripts resetting local accounts. Artifacts, blending with legitimate files, were found under default Windows system paths.

Security Recommendations

Organizations should audit Hyper-V usage and disable it where unnecessary. Monitoring for hidden VMs and unexpected imports using PowerShell and WMI activity is advised. Host-based network inspection should be enabled on systems with virtualization.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6414202
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1283596
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496907
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454083
downloads

News and reviews for Desktop Windows

Misery Delisted from Steam After DMCA Complaint

Misery removed from Steam after DMCA by GSC Game World. Developer disputes claims, plans response.

Read more

Announce Elden Ring: Nightreign DLC for FY2025 Release

FromSoftware plans to release Elden Ring: Nightreign DLC in FY2025, expanding on the Elden Ring universe.

Read more

Free Windows 10 Security Updates Require Enrollment

Windows 10 users must enroll in Extended Security Updates by 2025-11-08 to maintain protection.

Read more

Flyoobe Compromised: Caution Advised for Windows 10 Users

Flyoobe, a Windows 11 bypass tool, faces malware threats through fake versions, urging users to download only from the official GitHub.

Read more

Fake Flyoobe Tool Targets Windows 10 Users

Fraudsters are distributing a fake Flyoobe tool for Windows 11 installs, posing security risks.

Read more

Skopje '83 Demo Update Adds Performance Boost and Content

Indie studio Dark-1 releases updated demo for Skopje '83; new content, better performance. Early Steam discount until 2023-11-14.

Read more

NetEase Ends Partnership with Jackalyptic Games

NetEase has ended its collaboration with Jackalyptic Games, impacting the Warhammer MMO project and studio employees now seeking new positions.

Read more

Arc Raiders Exceeds Battlefield 6 in Steam Player Count

Arc Raiders draws large audience on Steam, surpassing Battlefield 6's peak players. Impact: increased accessibility in extraction shooter genre.

Read more

Nightingale November Update Enhances Gameplay with New Charms

The November 2025 Nightingale update adds charms, weapon buffs, and magic rebalances, promising a richer gaming experience.

Read more

Elestrals Awakened Hits Kickstarter Milestone with 2027 PC Release

Elestrals Awakened, a retro JRPG, breaks records on Kickstarter, set for PC release in 2027.

Read more