SYMBOLCOMMON_NAMEaka. SYNONYMS

Curly COMrades  (Back to overview)


Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ techniques such as Hyper-V abuse for EDR evasion and utilize proxy tools like Resocks, SSH, and Stunnel to gain access to internal networks. Their activities include repeated attempts to extract the NTDS database from domain controllers and establishing covert access through virtualization features on compromised Windows 10 machines.


Associated Families

There are currently no families associated with this actor.


References
2025-11-04BitdefenderAdrian Schipor, Martin Zugec, Victor Vrabie
Curly COMrades: Evasion and Persistence via Hidden Hyper-V Virtual Machines
Curly COMrades
2025-08-12BitdefenderVictor Vrabie
Curly COMrades: A New Threat Actor Targeting Geopolitical Hotbeds Victor Vrabie
RMS Curly COMrades

Credits: MISP Project