Russian spies hide malware in invisible Windows VMs

Russian spies hide malware in invisible Windows VMs - Professional coverage

According to TheRegister.com, Russian hacking group Curly COMrades is exploiting Microsoft’s Hyper-V hypervisor to create hidden Alpine Linux virtual machines that bypass endpoint security tools. The hidden environment uses only 120MB disk space and 256MB memory and hosts their custom reverse shell called CurlyShell plus a reverse proxy called CurlCat. Bitdefender senior security researcher Victor Vrabie revealed in a Tuesday report that the Romanian security firm, working with Georgia’s CERT, uncovered this campaign that began in July. The group executed remote commands on two computers to enable Hyper-V virtualization while disabling its management interface, then downloaded the lightweight VM containing their malware days later. Bitdefender has been tracking Curly COMrades since 2024 and says they support Russian geopolitical interests, having previously targeted judicial and government bodies in Georgia plus a Moldovan energy distribution company.

Special Offer Banner

How the attack works

Here’s the clever part: they’re using Microsoft’s own virtualization technology against itself. The attackers configure the VM to use Hyper-V’s Default Switch network adaptor, which means all the malicious traffic appears to come from the legitimate host machine’s IP address. Basically, your security tools see what looks like normal Windows traffic while the actual malware is running safely isolated in a hidden Linux environment.

And get this – they’re not even doing anything particularly exotic. They’re using standard Hyper-V features that are built right into Windows. The VM runs Alpine Linux, which is incredibly lightweight, and contains two custom implants written in C++ using the libcurl library. CurlyShell provides the reverse shell and uses cron jobs for persistence, while CurlCat wraps SSH traffic into HTTP requests to make everything look legit.

Why this matters

So what’s the big deal? Well, this represents a significant shift in how sophisticated attackers are thinking about evasion. As Vrabie noted, as EDR and XDR solutions become commodity tools, threat actors are getting smarter about bypassing them. They’re not just trying to hide malware – they’re hiding entire execution environments.

Think about it: if your security tools are only monitoring the host operating system, they might completely miss what’s happening inside a hidden virtual machine. The malware could be doing all sorts of nasty things while your endpoint protection reports everything’s fine. It’s like having burglars living in your attic while your home security system only monitors the main floors.

This isn’t an isolated case either. We’re seeing more attackers abuse legitimate system tools and features. Some ransomware gangs are even incorporating “EDR killers” into their malware arsenals. The days of relying solely on endpoint detection are clearly over.

Bitdefender’s detailed analysis shows this group has been active since at least their August campaign against Georgian targets. They’re not just random hackers – this appears to be state-aligned activity with clear geopolitical objectives.

What to do about it

The security recommendation here is pretty clear: you need defense in depth. Relying solely on endpoint detection won’t cut it anymore. Security teams should be monitoring for Hyper-V configuration changes, looking for unexpected virtualization activity, and implementing network-level detection.

Bitdefender has published a full list of indicators of compromise on GitHub, which is definitely worth checking out if you’re responsible for securing Windows environments. The bottom line? Assume your endpoints will be compromised and build your security strategy accordingly. Because the bad guys are definitely getting more creative about where they hide their tools.

19 thoughts on “Russian spies hide malware in invisible Windows VMs”

  1. Yesterday, while I was at work, my cousin stole my iphone and tested to see if it
    can survive a forty foot drop, just so she can be a youtube sensation. My apple ipad is now destroyed and she has 83 views.
    I know this is totally off topic but I had to share it with
    someone!

  2. Appreciating the time and effort you put into your blog and detailed information you
    present. It’s good to come across a blog every once in a while that
    isn’t the same out of date rehashed material. Great read!
    I’ve saved your site and I’m adding your RSS feeds to my Google account.

  3. Good day! This is kind of off topic but I
    need some advice from an established blog.
    Is it very hard to set up your own blog? I’m not very techincal
    but I can figure things out pretty fast.

    I’m thinking about setting up my own but I’m not sure where to start.
    Do you have any ideas or suggestions? Cheers

  4. When I initially commented I clicked the “Notify me when new comments are added” checkbox
    and now each time a comment is added I get several emails with the same
    comment. Is there any way you can remove people from that service?
    Many thanks!

  5. Today, while I was at work, my cousin stole my iphone and tested to see if it
    can survive a 30 foot drop, just so she can be a
    youtube sensation. My iPad is now broken and she has 83 views.
    I know this is totally off topic but I had to share it with someone!

  6. First off I want to say awesome blog! I had a quick
    question which I’d like to ask if you don’t mind.
    I was interested to know how you center yourself and clear your thoughts prior to writing.
    I have had a difficult time clearing my mind in getting my thoughts out.
    I do take pleasure in writing however it just seems like the first 10 to 15 minutes are generally wasted just
    trying to figure out how to begin. Any suggestions
    or tips? Many thanks!

  7. magnificent put up, very informative. I’m wondering why the other specialists of this sector do not notice this.
    You should proceed your writing. I’m sure, you’ve a huge readers’ base already!

  8. Hello just wanted to give you a quick heads up. The words in your article
    seem to be running off the screen in Firefox. I’m not sure if this is a format issue or something to do with internet browser compatibility but I figured I’d post to let you know.

    The layout look great though! Hope you get the problem solved soon. Kudos

  9. You actually make it seem so easy with your presentation but I find this
    matter to be actually something which I think I would never understand.
    It seems too complicated and extremely broad for me.
    I am looking forward for your next post, I’ll try to get the hang of it!

  10. Its like you read my mind! You seem to know so much about this,
    like you wrote the book in it or something. I think that you could do with a few pics to drive the
    message home a little bit, but instead of that, this is fantastic blog.
    A great read. I’ll definitely be back.

Leave a Reply

Your email address will not be published. Required fields are marked *