Curly COMrades — APT Profile
Curly COMrades is a Russia-aligned cyber-espionage threat actor first documented and named by Bitdefender in August 2025, with activity assessed back to at least late 2023. The group has targeted judicial and government bodies in Georgia and an energy distribution company in Moldova, aiming for long-term network access and credential theft (including NTDS extraction from domain controllers and LSASS dumping). It uses a custom three-stage .NET backdoor (MucorAgent) that hijacks COM/NGEN class identifiers for persistence and patches AMSI to run encrypted PowerShell, and later research documented its use of hidden Hyper-V virtual machines running Alpine Linux with custom CurlyShell/CurlCat implants to evade EDR detection; the name derives from its heavy use of curl.exe and COM hijacking.
Vendor research
Countries linked to this actor
Read the full analysis on IntelFusions