Curly COMrades: New Russian-Aligned Threat Actor Targeting Geopolitical Hotbeds
N2K NetworksSeptember 27, 202525 min144 views
22 connectionsΒ·40 entities in this videoβUnveiling Curly COMrades
- π‘ A newly identified Russian-aligned threat actor, dubbed "Curly COMrades," has been uncovered by Bitdefender Labs.
- π― This group is responsible for espionage campaigns targeting judicial, government, and energy organizations in Eastern Europe, specifically in regions geopolitically situated between Russia and Europe.
- ποΈ The group's activity was initially tracked from mid-2024, with evidence suggesting operations dating back to November 2023.
Tactics, Techniques, and Procedures (TTPs)
- π Curly COMrades focuses on achieving long-term network access, credential theft, and maintaining stealthy persistence.
- βοΈ A novel backdoor, MucorAgent, has been documented, which hijacks Windows CLSIDs and uses NGEN for covert execution.
- π The threat actor leverages a large network of legitimate but compromised websites as traffic relays, blending malicious activity with normal web traffic to evade detection.
- π They employ various methods for maintaining access, including SSH tunnels and custom SOCKS5 servers, demonstrating a persistent effort to regain access if discovered.
MucorAgent and Persistence Techniques
- π§ The MucorAgent is a .NET-based tool that executes PowerShell and utilizes a unique activation method.
- π οΈ It hijacks COM objects by modifying their target to execute the malicious agent instead of legitimate .NET framework components.
- β³ Activation relies on a disabled scheduled task that is triggered by the system's idle state during .NET pre-compilation (NGEN), making its execution unpredictable and difficult to detect.
- π΅οΈ This technique, combined with hijacking hidden COM classes, makes the agent's execution and persistence highly sophisticated and novel.
Operational Sophistication and Resilience
- π The group's use of compromised legitimate websites for command and control (C2) and traffic relay indicates a highly organized and advanced operation.
- π Curly COMrades demonstrates resilience by using multiple methods to re-establish access, including common binaries like SSH and tools like S tunnel to obfuscate traffic.
- π They are increasingly adopting a
Knowledge graph40 entities Β· 22 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters10 moments
Key Moments
Transcript92 segments
Full Transcript
Topics15 themes
Whatβs Discussed
Curly COMradesBitdefender LabsThreat ActorEspionageCybersecurityEastern EuropeMucorAgentPersistence TechniquesCOM HijackingNGENScheduled TasksSSH TunnelingCompromised WebsitesAPT GroupMalware Analysis
Smart Objects40 Β· 22 links
ProductsΒ· 6
EventsΒ· 4
PeopleΒ· 3
MediasΒ· 4
LocationsΒ· 4
CompaniesΒ· 11
ConceptsΒ· 8