• News/
  • https://www.bleepingcomputer.com/news/security/curly-comrades-cyberspies-hit-govt-orgs-with-custom-malware/

Curly COMrades cyberspies hit govt orgs with custom malware

BleepingComputer
·
Bill Toulas
·
Published Aug 12, 2025
·
Updated

A new cyber-espionage threat group has been using a new backdoor malware that provides persistent access through a seemingly inactive scheduled task. The threat actor's operations appear to support Russian interests by targeting government and judicial bodies in Georgia, and energy firms in Moldova. The attacker is currently tracked as Curly COMrades and has been active since mid-2024 and is using a custom three-stage mallware component that researchers call MucorAgent. In a report today, cybersecurity company Bitdefender describes MucorAgent as a "complex" piece of malware "engineered as a .NET stealthy tool capable of executing an AES-encrypted PowerShell script and uploading the resulting output to a designated server." The researchers named the threat actor Curly COMrades due to the heavy use of the curl.exe tool for data exfiltration and communicating with the command-and-control (C2) server, and because of hijacking Component Object Model (COM) objects during the attack. While no strong overlaps with known Russian APT groups have been found, the researchers say that the threat "group's operations align with the geopolitical goals of the Russian Federation." The researchers couldn't determine the initial access vector but observed the installation of multiple proxy agents, including the Go-based Resocks, across internal systems. Resocks is retrieved via curl.exe and registered as scheduled tasks or Windows services for persistence, communicating with the C2 via TCP 443 ...

Read full article

Affected Software

1 affected component
Bitdefender MucorAgent
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new cyber-espionage threat group called Curly COMrades that is targeting government organizations with custom backdoor malware.

2

What security implications are discussed?

The article highlights the persistent access provided by the malware through an inactive scheduled task, posing risks to government security.

3

What products or software are affected?

The affected software mentioned in the article is Bitdefender's MucorAgent.

4

What are the motivations behind the Curly COMrades attacks?

The threat actor appears to be operating in support of Russian interests by targeting governmental entities.

5

How is the malware delivered to the target organizations?

The custom malware is delivered through a sophisticated method involving a seemingly inactive scheduled task.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203