216.73.216.6

Evasion and Persistence via Hidden Hyper-V Virtual Machines

· Published 05/11/2025 09:27 · Modified 05/11/2025 09:49

Export JSON

Essential information

Published
05/11/2025 09:27
Modified
05/11/2025 09:49
Tags
2025-11-05 alpine linux curlcat curlyshell evasion hyper-v kerberos lateral movement persistence powershell proxy reverse shell virtualization
Related entities
4 observables, 1 intrusion sets (apt), 11 techniques (mitre), 2 malware, 2 others

Description

This investigation uncovered new tools and techniques used by the Curly COMrades threat actor to establish covert, long-term access to victim networks. The attackers exploited on compromised Windows 10 machines to create hidden remote operating environments. They deployed a minimalistic -based virtual machine hosting custom malware for and operations. This approach effectively bypassed traditional host-based EDR detections. The threat actor also demonstrated through scripts, ticket manipulation, and local account creation. International collaboration with the Georgian CERT aided in analyzing the command and control infrastructure.

External references