logo

Russian hackers abuse Hyper-V to hide malware in Linux VMs

ID: eb99c0fb-32e7-5f75-a939-f9307246479a

STIX ID: report--eb99c0fb-32e7-5f75-a939-f9307246479a

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-11-04

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Bitdefender investigators uncovered an active Curly COMrades operation in which the group enabled Hyper-V on compromised Windows hosts, deployed a minimal Alpine Linux VM (named to resemble WSL) to run custom ELF implants (CurlyShell reverse shell and CurlCat reverse proxy) and used VM networking to blend C2 traffic with host traffic. The actors also used PowerShell scripts for LSASS Kerberos ticket injection and Group Policy-based account creation to achieve persistence and lateral pivoting, enabling stealthy cyber-espionage against government and energy sector targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.