Russian hackers abuse Hyper-V to hide malware in Linux VMs
ID: eb99c0fb-32e7-5f75-a939-f9307246479a
STIX ID: report--eb99c0fb-32e7-5f75-a939-f9307246479a
Feed Name: Bleeping Computer
Bitdefender investigators uncovered an active Curly COMrades operation in which the group enabled Hyper-V on compromised Windows hosts, deployed a minimal Alpine Linux VM (named to resemble WSL) to run custom ELF implants (CurlyShell reverse shell and CurlCat reverse proxy) and used VM networking to blend C2 traffic with host traffic. The actors also used PowerShell scripts for LSASS Kerberos ticket injection and Group Policy-based account creation to achieve persistence and lateral pivoting, enabling stealthy cyber-espionage against government and energy sector targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
