Another Linux Malware Discovered
Russian hackers use Hyper-V to hide malware within Linux virtual machines.
Curly COMrade – a Russian hacking group that's been active since 2024 and is aligned with Russian political movements – has been abusing the Microsoft Hyper-V within Windows to bypass detection by creating a virtual machine (VM) based on Alpine Linux to deploy malware.
The VM only uses 120MB of disk space and 256MB of memory, making it less detectable. Once the VM has been deployed, the malware uses the CurlyShell reverse shell and the CurlCat reverse proxy for stealth and communication.
According to Bitdefender, "By isolating the malware and its execution environment within a VM, the attackers effectively bypassed many traditional host-based EDR [endpoint detection and response] detections. EDR needs to be complemented by host-based network inspection to detect C2 traffic escaping the VM, and proactive hardening tools to restrict the initial abuse of native system binaries."
During that same investigation, Bitdefender discovered a PowerShell script that was created specifically for remote execution was employed to abuse Kerberos tickets to further expand the Curly toolkit.
Both CurlyShell and CurlyCat were written in C++ and built around the libcurl library.
As far as mitigation is concerned, Bitdefender suggests that organizations "must detect abnormal access to the LSASS process and suspicious Kerberos ticket creation or injection attempts, which occur outside the VM and are highly detectable." The report then suggests using "GravityZone EDR/XDR capabilities to detect malicious access to credential processes and mitigate memory-based attacks. For organizations operating with a lean security staff, adopting Managed Detection and Response (MDR) services offers an effective solution."
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Another Linux Malware Discovered
Russian hackers use Hyper-V to hide malware within Linux virtual machines.
-
TUXEDO Computers Announces a New InfinityBook
TUXEDO Computers is at it again with a new InfinityBook that will meet your professional and gaming needs.
-
SUSE Dives into the Agentic AI Pool
SUSE becomes the first open source company to adopt agentic AI with SUSE Enterprise Linux 16.
-
Linux Now Runs Most Windows Games
The latest data shows that nearly 90 percent of Windows games can be played on Linux.
-
Fedora 43 Has Finally Landed
The Fedora Linux developers have announced their latest release, Fedora 43.
-
KDE Unleashes Plasma 6.5
The Plasma 6.5 desktop environment is now available with new features, improvements, and the usual bug fixes.
-
Xubuntu Site Possibly Hacked
It appears that the Xubuntu site was hacked and briefly served up a malicious ZIP file from its download page.
-
LMDE 7 Now Available
Linux Mint Debian Edition, version 7, has been officially released and is based on upstream Debian.
-
Linux Kernel 6.16 Reaches EOL
Linux kernel 6.16 has reached its end of life, which means you'll need to upgrade to the next stable release, Linux kernel 6.17.
-
Amazon Ditches Android for a Linux-Based OS
Amazon has migrated from Android to the Linux-based Vega OS for its Fire TV.
