New ‘Curly COMrades’ APT Targets Georgia and Moldova with NGEN COM Hijacking

Published:

spot_img

Unveiling the Curly COMrades: A New Cyber Threat

Introduction to the Curly COMrades

In recent cybersecurity updates, a new, unidentified threat group known as Curly COMrades has emerged, actively targeting organizations in Georgia and Moldova. This group is suspected of engaging in cyber espionage efforts aimed at establishing prolonged access to the networks of their targets.

Targeting Key Institutions

The Curly COMrades have primarily focused on judicial and governmental institutions in Georgia, as well as an energy distribution company in Moldova. Their activities have been meticulously tracked by Romanian cybersecurity firm Bitdefender since mid-2024, although indications suggest that their operations may have commenced even earlier.

Attack Techniques

Bitdefender’s report highlights the group’s attempts to extract the NTDS database, a critical component storing user password hashes and authentication details within a Windows network. Additionally, they have shown interest in dumping LSASS (Local Security Authority Subsystem Service) memory from specific systems, a technique often used to recover active user credentials and plaintext passwords from machines where users are logged in.

A Methodical Approach

According to Martin Zugec, Bitdefender’s Technical Solutions Director, the attackers employ a consistent and methodical strategy. "Our analysis suggests they have combined standard attack techniques with tailored implementations to blend into legitimate system operations," he explained. The group’s behavior has been characterized by repeated trial-and-error tactics, which allow them to maintain a discreet and resilient foothold across numerous systems.

Exploiting Legitimate Tools

Curly COMrades have effectively leveraged legitimate tools such as Resocks, SSH, and Stunnel to gain multiple entry points into internal networks. These tools facilitate remote command execution using stolen credentials, enhancing their capabilities without drawing attention to their activities.

The Role of MucorAgent

A significant facet of the Curly COMrades’ attack strategy involves a custom backdoor known as MucorAgent. This tool hijacks Class Identifiers (CLSIDs) linked to the Native Image Generator (Ngen), a .NET Framework service that pre-compiles assemblies. By doing so, they create a means for persistence through a seemingly inactive scheduled task that the operating system can trigger unpredictably.

MucorAgent functions through a three-stage deployment process, executing encrypted PowerShell scripts and transmitting the output back to designated servers. Bitdefender indicates that the design of this backdoor suggests it was developed to operate as a covert tool capable of delivering payloads at regular intervals.

Technical Prowess and Adaptation

The tactical capabilities displayed by Curly COMrades underscore their technical sophistication. Abusing Ngen allows them to execute commands under the highly privileged SYSTEM account, enhancing their potential for undetected manipulation within compromised networks.

Utilizing Compromised Websites

Curly COMrades are also known to utilize legitimate but compromised websites as relays during command-and-control (C2) operations. This strategy serves to obscure their malicious traffic, enabling them to blend in with normal network activity and avoid detection.

Tools of the Trade

The attacks deployed by Curly COMrades involve a variety of recognized tools, many of which are publicly available:

  • CurlCat: Facilitates data transfer between input and output streams and C2 servers via HTTPS, routing traffic through compromised sites.
  • RuRat: A legitimate remote monitoring tool that provides persistent access.
  • Mimikatz: Used for extracting credentials from system memory.
  • Common built-in commands like netstat, tasklist, systeminfo, ipconfig, and ping, which aid in system discovery.
  • PowerShell scripts that utilize curl for exfiltrating sensitive data, including credentials and internal domain information.

Conclusion: A Persistent Threat

The activities of Curly COMrades reflect a highly persistent and adaptable cyber threat. They have demonstrated an ability to blend traditional techniques with customized methods, establishing long-term access within targeted environments. This campaign exposes a growing trend among threat actors: a reliance on familiar, publicly available tools and techniques to maintain stealth and minimize detection, making the threat landscape more complex for cybersecurity professionals.

spot_img

Related articles

Recent articles

Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities, Revealing Vulnerabilities and Response Gaps

In a significant cybersecurity incident, over 30 water and wastewater utilities in Minnesota were targeted by a coordinated cyberattack between July 26 and July...

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...