Also known as: Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, insurance industries, UNC961, Prophet Spider, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, Samurai Panda, PLA Navy, APT4, Wisp Team, APT35, IMPERIAL KITTEN, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, BOHRIUM, DEV-0228, UNC2596, Scattered Spider, Blue Echidna, GOFFEE, Fluffy Wolf, LuoYu, CASCADE PANDA, Qilin, file transfer tools, Secret Blizzard, Google Sheets, personal photos, UAC-0190, GRU, FakeUpdates, Mustard Tempest, Purple Vallhund, UNC1543, MSC EvilTwin, LARVA-208, Water Gamayun, Laundry Bear, UAC-0063, LummaC, LummaC2, Roshtyak, Storm-0856, Awaken Likho, PseudoGamaredon, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ techniques such as Hyper-V abuse for EDR evasion and utilize proxy tools like Resocks, SSH, and Stunnel to gain access to internal networks. Their activities include repeated attempts to extract the NTDS database from domain controllers and establishing covert access through virtualization features on compromised Windows 10 machines.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Curly COMrades is a Russian-affiliated threat actor identified by Amazon Threat Intelligence and Bitdefender, leveraging advanced techniques such as Hyper-V abuse for endpoint detection response (EDR) evasion and proxy tools to infiltrate networks. Their operations focus on extracting sensitive data from domain controllers and establishing covert access through virtualization features on Windows 10 systems.
Goals & Targeting
Curly COMrades appears to target organizations with high-value data, particularly those in sectors critical to national security, such as government, defense, and critical infrastructure. Their focus on NTDS extraction and covert network access suggests an intent to gather intelligence or achieve strategic advantage by maintaining long-term persistence within target networks. The use of Russian-linked proxy tools and the overall operational methodology imply a possible alignment with state-sponsored objectives, although direct attribution remains unconfirmed. Their targeting pattern suggests a preference for organizations with access to sensitive internal networks and systems, making them a significant threat to entities in sectors with geopolitical significance.
Enhanced Description
Curly COMrades is a sophisticated threat actor linked to Russian interests, as reported by Amazon Threat Intelligence and Bitdefender. The group employs a range of stealthy tactics, including the exploitation of Hyper-V virtualization to evade EDR systems, and utilizes proxy infrastructures such as Resocks, SSH, and Stunnel to maintain covert command-and-control (C2) channels. A key focus of their activities involves repeated attempts to extract the NTDS database from domain controllers, which could provide access to user credentials and other sensitive information. Additionally, they exploit virtualization features on compromised Windows 10 hosts to establish persistent, hard-to-detect access to internal networks. This strategy highlights their emphasis on long-term presence within target environments and the ability to bypass modern security defenses. The actor’s use of proxy-based C2 and virtualization techniques suggests a high level of operational sophistication, as well as a clear intent to avoid attribution and maintain access over extended periods.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Curly COMrades is associated with targeted intrusions focused on data exfiltration and long-term network compromise. Campaigns often involve exploiting virtualization and proxy tools to evade detection, with a clear emphasis on accessing domain controllers for NTDS extraction. The actor’s operational tempo suggests a low-and-slow approach, indicative of a focus on stealth and persistence. Notable past operations include infiltration of Windows networks through compromised endpoints, leveraging virtualization features to avoid direct visibility by security systems. However, specific campaign timelines and geographic targeting remain unclear due to limited publicly available data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat actor’s identity and capabilities are supported by credible indicators from Amazon Threat Intelligence and Bitdefender, providing medium to high confidence in the reported activities. However, gaps exist regarding the actor’s sophistication level, primary motivation, targeted sectors, and specific countries of interest. Further analysis of IOCs and network telemetry could improve confidence in attribution and expand understanding of their full operational scope.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics