New ‘Curly’ threat actor found targeting sensitive organizations in Georgia, Moldova
ID: 91ee5234-440b-5409-b27a-127d6e67c5a8
STIX ID: report--91ee5234-440b-5409-b27a-127d6e67c5a8
Feed Name: The Record from Recorded Future News
Researchers attribute an ongoing espionage campaign to a suspected Russia-aligned group dubbed “Curly COMrades,” active since late 2024 and targeting government, judicial, and energy organizations in Georgia and Moldova. The actors aim to maintain long-term access and harvest credentials using a mix of publicly available tools and custom malware (MucorAgent), hijacked Windows scheduled tasks, and compromised legitimate websites as C2/exfiltration relays to blend malicious traffic and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
