logo

New ‘Curly’ threat actor found targeting sensitive organizations in Georgia, Moldova

ID: 91ee5234-440b-5409-b27a-127d6e67c5a8

STIX ID: report--91ee5234-440b-5409-b27a-127d6e67c5a8

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-08-13

Date Updated: 2026-05-01

...
...

Researchers attribute an ongoing espionage campaign to a suspected Russia-aligned group dubbed “Curly COMrades,” active since late 2024 and targeting government, judicial, and energy organizations in Georgia and Moldova. The actors aim to maintain long-term access and harvest credentials using a mix of publicly available tools and custom malware (MucorAgent), hijacked Windows scheduled tasks, and compromised legitimate websites as C2/exfiltration relays to blend malicious traffic and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.