Skip to main content

Curly Comrades: Unpacking a Sophisticated APT Group Targeting Geopolitical Hotbeds

N2K NetworksSeptember 27, 202526 min425 views
24 connections·40 entities in this video→

The "Curly Comrades" Threat Actor

  • 🎯 The "Curly Comrades" APT group, identified by Bitdefender, targets regions geopolitically situated between Russia and Europe.
  • πŸ’‘ The group's name is derived from their frequent use of curl.exe and their technique of hijacking COM objects for persistence.
  • πŸ’° Their primary motivation appears to be long-term data exploitation, indicating sophisticated espionage activities.

Technical Sophistication and Persistence

  • 🧩 A core tool used is the Mukor agent, written in .NET, which executes PowerShell and employs a novel activation method.
  • βš™οΈ Mukor agent hijacks .NET framework's COM handlers and utilizes a scheduled task triggered by system idle time for execution, making it highly stealthy.
  • πŸ” This technique relies on the .NET JIT compilation process and a disabled-by-default scheduled task, making its activation unpredictable.
  • 🌐 The group leverages a large network of legitimate, compromised websites as traffic, suggesting a broader infrastructure than initially observed.

Operational Tactics and Resilience

  • πŸ”‘ Initial access methods remain unknown, a common challenge in forensic investigations.
  • πŸ”„ The group demonstrates a strong focus on proxying access and maintaining multiple backdoors, using tools like SSH and custom SOCKS servers.
  • πŸ“ˆ Resilience is a key trait, with the group employing various methods to regain access if detected and removed.
  • πŸ’» There's a trend towards using legitimate, common binaries (living off the land) and abusing Remote Monitoring and Management (RMM) tools, rather than solely relying on custom malware.

Recommendations for Defense

  • πŸ›‘οΈ Organizations need EDR/XDR solutions to detect suspicious behavior and reduce attacker dwell time.
  • πŸ§‘β€πŸ’» A properly staffed and trained Security Operations Center (SOC) or managed detection and response service is crucial for responding to alerts.
  • πŸ“š Staying updated with the latest research on threat actor TTPs, especially living-off-the-land techniques and RMM abuse, is vital for effective defense.
Knowledge graph40 entities Β· 24 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters9 moments

Key Moments

Transcript93 segments

Full Transcript

Topics15 themes

What’s Discussed

Curly ComradesAPT GroupCyber EspionageMalware AnalysisMukor AgentDLL SideloadingCOM HijackingScheduled Tasks.NET FrameworkLiving Off The LandRMM AbuseBitdefenderGeopolitical TargetingNetwork SecurityThreat Intelligence
Smart Objects40 Β· 24 links
ProductsΒ· 10
CompaniesΒ· 11
PeopleΒ· 4
MediaΒ· 1
EventsΒ· 3
ConceptsΒ· 10
LocationΒ· 1