Evasion and Persistence via Hidden Hyper-V Virtual Machines
Essential information
- Published
- 05/11/2025 09:27
- Modified
- 05/11/2025 09:49
- Tags
- 2025-11-05 alpine linux curlcat curlyshell evasion hyper-v kerberos lateral movement persistence powershell proxy reverse shell virtualization
- Related entities
- 4 observables, 1 intrusion sets (apt), 11 techniques (mitre), 2 malware, 2 others
Description
This investigation uncovered new tools and techniques used by the Curly COMrades threat actor to establish covert, long-term access to victim networks. The attackers exploited Hyper-V virtualization on compromised Windows 10 machines to create hidden remote operating environments. They deployed a minimalistic Alpine Linux-based virtual machine hosting custom malware for reverse shell and proxy operations. This approach effectively bypassed traditional host-based EDR detections. The threat actor also demonstrated persistence through PowerShell scripts, Kerberos ticket manipulation, and local account creation. International collaboration with the Georgian CERT aided in analyzing the command and control infrastructure.