Curly COMrades: Russia-Linked Cyber Espionage Threatens Georgia and Moldova with Sneaky Tactics
Curly COMrades, a new cyber espionage group, targets Georgia and Moldova using the curl utility and COM object hijacking. Their method? A mix of off-the-shelf tools, trial-and-error, and stealthy persistence—like a cat burglar with a penchant for tech. Clearly, cyber snooping is now as easy as curling up with a good book.

Hot Take:
***Looks like the Curly COMrades are curling their way into the cybersecurity hall of fame by blending in with the good guys! Who knew espionage could be so stealthy and stylish?***
Key Points:
– Curly COMrades are targeting Georgia and Moldova with long-term espionage campaigns.
– They use a mix of standard and custom tools to maintain a low profile.
– The group started operations as early as November 2023, if not earlier.
– They exploit legitimate tools like Resocks, SSH, and Stunnel for multiple network entry points.
– Their bespoke backdoor, MucorAgent, showcases advanced technical prowess.