Curly COMrades is a Russian-aligned threat actor known for NTDS database theft and Hyper-V abuse for EDR evasion.
Analyst brief
Curly COMrades is a threat actor believed to operate in support of Russian interests. They focus on gaining access to internal networks and repeatedly attempting to extract the NTDS database from domain controllers. Key TTPs include Hyper-V abuse for EDR evasion and the use of proxy tools like Resocks, SSH, and Stunnel to maintain covert access. Defenders should prioritize monitoring for anomalous Hyper-V activity, suspicious outbound proxy connections, and repeated NTDS access attempts.
Curly COMrades
unknown
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ techniques such as Hyper-V abuse for EDR evasion and utilize proxy tools like Resocks, SSH, and Stunnel to gain access to internal networks. Their activities include repeated attempts to extract the NTDS database from domain controllers and establishing covert access through virtualization features on compromised Windows 10 machines.