Curly COMrades

Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:22:15

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:us country_code:gb country_code:de

Context

Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ techniques such as Hyper-V abuse for EDR evasion and utilize proxy tools like Resocks, SSH, and Stunnel to gain access to internal networks. Their activities include repeated attempts to extract the NTDS database from domain controllers and establishing covert access through virtualization features on compromised Windows 10 machines.

Reports & references

  • bitdefender.com — Curly Comrades Evasion Persistence Hidden Hyper V Virtual Machines (report)
  • bitdefender.com — Curly Comrades New Threat Actor Targeting Geopolitical Hotbeds (report)

External references