Curly Comrades: Unpacking a Sophisticated APT Group Targeting Geopolitical Hotbeds
N2K NetworksSeptember 27, 202526 min425 views
24 connectionsΒ·40 entities in this videoβThe "Curly Comrades" Threat Actor
- π― The "Curly Comrades" APT group, identified by Bitdefender, targets regions geopolitically situated between Russia and Europe.
- π‘ The group's name is derived from their frequent use of
curl.exeand their technique of hijacking COM objects for persistence. - π° Their primary motivation appears to be long-term data exploitation, indicating sophisticated espionage activities.
Technical Sophistication and Persistence
- π§© A core tool used is the Mukor agent, written in .NET, which executes PowerShell and employs a novel activation method.
- βοΈ Mukor agent hijacks .NET framework's COM handlers and utilizes a scheduled task triggered by system idle time for execution, making it highly stealthy.
- π This technique relies on the .NET JIT compilation process and a disabled-by-default scheduled task, making its activation unpredictable.
- π The group leverages a large network of legitimate, compromised websites as traffic, suggesting a broader infrastructure than initially observed.
Operational Tactics and Resilience
- π Initial access methods remain unknown, a common challenge in forensic investigations.
- π The group demonstrates a strong focus on proxying access and maintaining multiple backdoors, using tools like SSH and custom SOCKS servers.
- π Resilience is a key trait, with the group employing various methods to regain access if detected and removed.
- π» There's a trend towards using legitimate, common binaries (living off the land) and abusing Remote Monitoring and Management (RMM) tools, rather than solely relying on custom malware.
Recommendations for Defense
- π‘οΈ Organizations need EDR/XDR solutions to detect suspicious behavior and reduce attacker dwell time.
- π§βπ» A properly staffed and trained Security Operations Center (SOC) or managed detection and response service is crucial for responding to alerts.
- π Staying updated with the latest research on threat actor TTPs, especially living-off-the-land techniques and RMM abuse, is vital for effective defense.
Knowledge graph40 entities Β· 24 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters9 moments
Key Moments
Transcript93 segments
Full Transcript
Topics15 themes
Whatβs Discussed
Curly ComradesAPT GroupCyber EspionageMalware AnalysisMukor AgentDLL SideloadingCOM HijackingScheduled Tasks.NET FrameworkLiving Off The LandRMM AbuseBitdefenderGeopolitical TargetingNetwork SecurityThreat Intelligence
Smart Objects40 Β· 24 links
ProductsΒ· 10
CompaniesΒ· 11
PeopleΒ· 4
MediaΒ· 1
EventsΒ· 3
ConceptsΒ· 10
LocationΒ· 1