Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Curly COMrades

Also known as: Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, insurance industries, UNC961, Prophet Spider, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, Samurai Panda, PLA Navy, APT4, Wisp Team, APT35, IMPERIAL KITTEN, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, BOHRIUM, DEV-0228, UNC2596, Scattered Spider, Blue Echidna, GOFFEE, Fluffy Wolf, LuoYu, CASCADE PANDA, Qilin, file transfer tools, Secret Blizzard, Google Sheets, personal photos, UAC-0190, GRU, FakeUpdates, Mustard Tempest, Purple Vallhund, UNC1543, MSC EvilTwin, LARVA-208, Water Gamayun, Laundry Bear, UAC-0063, LummaC, LummaC2, Roshtyak, Storm-0856, Awaken Likho, PseudoGamaredon, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon

Description

Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ techniques such as Hyper-V abuse for EDR evasion and utilize proxy tools like Resocks, SSH, and Stunnel to gain access to internal networks. Their activities include repeated attempts to extract the NTDS database from domain controllers and establishing covert access through virtualization features on compromised Windows 10 machines.

Goals & Targeting

Targeted Sectors

Telecommunications
Financial services
Government
Manufacturing
Defense
Transportation
Energy
Education
Healthcare
Critical infrastructure
Aerospace
Retail
Aviation
Food agriculture
Construction
Media
Oil gas
Utilities
Maritime
Entertainment
Mining
Pharmaceutical
Chemical
Information technology
Non profit
Legal services
Hospitality

Targeted Countries / Regions

RU
US
UA
CN
BY
CA
BR
IR
KZ
TW
GB
FR
SG
VN
TR
JP
EG
IL
DE
RO
NL
KP
AU
IN
MX
ES
IT
SA

AI Analysis

· 1 week ago

Executive Summary

Curly COMrades is a Russian-affiliated threat actor identified by Amazon Threat Intelligence and Bitdefender, leveraging advanced techniques such as Hyper-V abuse for endpoint detection response (EDR) evasion and proxy tools to infiltrate networks. Their operations focus on extracting sensitive data from domain controllers and establishing covert access through virtualization features on Windows 10 systems.

Goals & Targeting

Curly COMrades appears to target organizations with high-value data, particularly those in sectors critical to national security, such as government, defense, and critical infrastructure. Their focus on NTDS extraction and covert network access suggests an intent to gather intelligence or achieve strategic advantage by maintaining long-term persistence within target networks. The use of Russian-linked proxy tools and the overall operational methodology imply a possible alignment with state-sponsored objectives, although direct attribution remains unconfirmed. Their targeting pattern suggests a preference for organizations with access to sensitive internal networks and systems, making them a significant threat to entities in sectors with geopolitical significance.

Enhanced Description

Curly COMrades is a sophisticated threat actor linked to Russian interests, as reported by Amazon Threat Intelligence and Bitdefender. The group employs a range of stealthy tactics, including the exploitation of Hyper-V virtualization to evade EDR systems, and utilizes proxy infrastructures such as Resocks, SSH, and Stunnel to maintain covert command-and-control (C2) channels. A key focus of their activities involves repeated attempts to extract the NTDS database from domain controllers, which could provide access to user credentials and other sensitive information. Additionally, they exploit virtualization features on compromised Windows 10 hosts to establish persistent, hard-to-detect access to internal networks. This strategy highlights their emphasis on long-term presence within target environments and the ability to bypass modern security defenses. The actor’s use of proxy-based C2 and virtualization techniques suggests a high level of operational sophistication, as well as a clear intent to avoid attribution and maintain access over extended periods.

Key Capabilities

  • Hyper-V abuse for EDR evasion
  • Proxy-based C2 using Resocks, SSH, and Stunnel
  • NTDS database extraction from domain controllers
  • Exploitation of virtualization features on Windows 10
  • Covert network access establishment through stealthy infrastructure

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access

ATT&CK Techniques

T1055.003: Abuse of Hyper-V or VMware Tools to bypass EDR
T1071.001: Use of standard non-secure protocols (SSH, DNS)
T1539: Extracting Data from NTDS
T1046: Native API
T1070.004: Clearing Windows Event Logs

Software / Tooling

Resocks
SSH
Stunnel
Hyper-V

Campaigns & Victims

Curly COMrades is associated with targeted intrusions focused on data exfiltration and long-term network compromise. Campaigns often involve exploiting virtualization and proxy tools to evade detection, with a clear emphasis on accessing domain controllers for NTDS extraction. The actor’s operational tempo suggests a low-and-slow approach, indicative of a focus on stealth and persistence. Notable past operations include infiltration of Windows networks through compromised endpoints, leveraging virtualization features to avoid direct visibility by security systems. However, specific campaign timelines and geographic targeting remain unclear due to limited publicly available data.

IOC Patterns

  • NTDS database extraction attempts from domain controllers
  • C2 traffic using Resocks, SSH, or Stunnel proxies
  • Hyper-V-related processes or configurations on Windows 10 hosts
  • Unusual network traffic patterns indicative of data exfiltration

Recommended Actions

  • Implement advanced EDR solutions with detection capabilities for Hyper-V abuse and proxy-based C2 activity
  • Monitor domain controllers for NTDS extraction attempts and enforce strict access controls
  • Deploy network segmentation to limit lateral movement within compromised environments
  • Regularly audit virtualization configurations and ensure patching of Windows 10 hosts
  • Conduct employee training to detect and report suspicious network activity or unauthorized tool usage

Suggested Tags

APT
espionage
Russian-affiliated
infrastructure-targeting
EDR-evasion

Confidence Assessment

The threat actor’s identity and capabilities are supported by credible indicators from Amazon Threat Intelligence and Bitdefender, providing medium to high confidence in the reported activities. However, gaps exist regarding the actor’s sophistication level, primary motivation, targeted sectors, and specific countries of interest. Further analysis of IOCs and network telemetry could improve confidence in attribution and expand understanding of their full operational scope.

ATT&CK Techniques

1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. ics-cert.kaspersky.com — Cited by web research for: APT44
  3. cert.europa.eu — Cited by web research for: WhatsApp
  4. thehackernews.com — Cited by web research for: CVE-2025-26633
  5. businessinsights.bitdefender.com — Cited by web research for: ssh.exe
  6. businessinsights.bitdefender.com — Cited by web research for: 1.rar

Intel Summary

1

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

APT
espionage
Russian-affiliated
infrastructure-targeting
EDR-evasion

Details

MITRE ID
APT4
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.