κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / New ‘Curly COMrades’ APT Hackers Attacking Targeting Critical Organizations in Countries
άμυνα
.

New ‘Curly COMrades’ APT Hackers Attacking Targeting Critical Organizations in Countries

13/08/2025

A sophisticated new threat actor group dubbed “Curly COMrades” has emerged as a significant cybersecurity concern, conducting targeted espionage campaigns against critical organizations in countries experiencing substantial geopolitical shifts.

The group has been actively pursuing long-term network access and credential theft operations since mid-2024, with a particular focus on judicial and government bodies in Georgia, as well as energy distribution companies in Moldova.

The threat actor’s operations represent a methodical approach to cyber espionage, characterized by their heavy reliance on proxy tools and strategic use of compromised legitimate websites as traffic relays.

This tactic significantly complicates detection efforts by blending malicious communications with normal network activity, allowing them to bypass security defenses that typically trust known domains while obscuring their true infrastructure.

Bitdefender analysts identified the group’s primary objective as maintaining persistent access to target networks while systematically harvesting valid credentials.

The attackers repeatedly attempted to extract the NTDS database from domain controllers, which serves as the primary repository for user password hashes and authentication data in Windows networks.

Additionally, they focused on dumping LSASS memory from specific systems to recover active user credentials, including potentially plain-text passwords from machines where users remained logged in.

The naming convention “Curly COMrades” reflects both the group’s technical methodologies and a deliberate attempt to de-glamorize cybercrime.

Resocks acts as a relay point into a compromised network. In this case, Network A represents an attacker, and Network B represents a victim (Source – Bitdefender)

The designation stems from their extensive use of curl.exe for command-and-control communications and data exfiltration, combined with their sophisticated exploitation of Component Object Model (COM) objects for persistence mechanisms.

The most technically sophisticated aspect of Curly COMrades’ arsenal involves their deployment of MucorAgent, a previously unknown three-stage malware that employs an innovative persistence mechanism through CLSID hijacking.

This approach targets the Native Image Generator (NGEN), a default Windows .NET Framework component that pre-compiles assemblies for improved performance.

The malware establishes persistence by hijacking the COM handler with CLSID {de434264-8fe9-4c0b-a83b-89ebeebff78e}, which is associated with the “.NET Framework NGEN v4.0.30319 Critical” scheduled task.

While this task remains disabled by default, the Windows operating system periodically enables and executes it during unpredictable intervals, such as system idle times or new application deployments.

reg add HKEY_USERS<SID>SOFTWAREClassesCLSID{de434264-8fe9-4c0b-a83b-89ebeebff78e}InprocServer32 /t REG_SZ /d “C:WindowsSystem32mscoree.dll” /F
reg add HKEY_USERS<SID>SOFTWAREClassesCLSID{de434264-8fe9-4c0b-a83b-89ebeebff78e}InprocServer32 /v Assembly /t REG_SZ /d “TaskLauncher, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null” /F

This technique provides several advantages for the attackers, including stealth execution under the highly privileged SYSTEM account and covert access restoration during legitimate system optimization processes.

The unpredictability of NGEN task execution times suggests that attackers likely employed parallel, more reliable triggers to ensure consistent access to compromised systems.

This innovative approach to COM hijacking in conjunction with NGEN represents an unprecedented persistence mechanism that demonstrates the group’s sophisticated understanding of Windows internals and their commitment to maintaining long-term network access.

Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

3 signs that you need a new CPU instead of a GPU

When you experience lower average frame rates or FPS drops, it's easy to assume that your graphics card is the culprit. After all, it's the main component that drives the visuals while you're gaming. However, the issue is that your GPU isn't always the primary cause of all your FPS issues. Although it does most of the heavy lifting in graphically demanding workloads, your CPU plays an equally … [Read More...]

The 3 PlayStation Plus games announced at State of Play you have to download to your PS5

PlayStation has been building up the catalog of classics and new titles available to players through the PlayStation Plus game catalog. With the September 2025 State of Play presentation, that catalog of titles for PS5 owners is continuing to get larger, offering a variety of games to play on the console. Unlike previous showings of State of Play, some highly requested and classic games are making … [Read More...]

5 productivity apps that made my NAS more useful than Google Workspace

Google Workspace is the industry default productivity suite, and rightly so — it’s fast, reliable, has excellent integrations, and offers handy collaboration features. However, it is just another subscription added to your credit card, which starts to bother you, especially if your team size is growing. Source: xda-developers.com … [Read More...]

6 tiny self-hosting tools that save me hours every week

If you are like me, you love the idea of self-hosting, but hate the thought of endless configuration and maintenance. The truth is, self-hosting doesn’t have to be a major time sink – it can actually be a massive time saver. I have spent months testing and refining my setup, and in the process, I have found tiny set-it-and-forget-it tools that work tirelessly in the background. Source: … [Read More...]

4 video game franchises that have lost their identity

Every successful game franchise has something that makes it unique: a style, a story, or a gameplay mechanic that players fall in love with. But when a series strays too far from its roots, that identity starts to fade. Here are four big franchises that lost touch with what made them special. Source: xda-developers.com … [Read More...]

Waffles eat Bluesky

For the past few days, my Bluesky feed has been increasingly filled with mysterious posts about waffles. The back-and-forth seems to have started with a tongue-in-cheek post by Jerry Chen lampooning a form of social media sanctimoniousness that’s become all too recognizable on Bluesky: “(bluesky user bursts into Waffle House) OH SO YOU HATE PANCAKES??” Bluesky CEO Jay Graber quoted this … [Read More...]

Jane Goodall’s death triggered the premiere of Netflix’s new show

EntertainmentIn what is likely her final interview, Goodall pulls no punches.Oct 5, 2025, 8:34 PM UTCTerrence O'Brien is the Verge’s weekend editor. He has over 18 years of experience, including 10 years as managing editor at Engadget.For the last several years Netflix has been quietly banking episodes of a new show called Famous Last Words, interviews with famous people entering their twilight … [Read More...]

Windows 11 25H2 reminds me why swapping to Linux was the best idea I've had this year

When was the last time you were deeply, truly keen to check out a new build of Windows? For me, I think the last time I was really wowed by a Windows build was with Windows 7. 8.1 wasn't too much of a jump, and Windows 10 was cozy, but not too exciting. Windows 11 went in the wrong direction for me; it didn't so much as innovate as it did remove key features from Windows without much rhyme or … [Read More...]

5 ways mice can easily become more user-repairable

We use peripherals like keyboards and mice nearly every minute our PCs are awake, yet they seem to draw the short straw in terms of innovation. We’ve had a solid run with mechanical keyboards, where a vibrant community has pushed the industry from soldered, inaccessible boards to hot-swappable, endlessly customizable typing instruments. We’ve seen PC cases evolve with modularity and ease-of-access … [Read More...]

Suspect arrested after threats against TikTok’s Culver City headquarters

Police say they have arrested a suspect allegedly connected to multiple online threats that led TikTok to evacuate its headquarters near Los Angeles on Friday. A press release from the Culver City Police Department says that TikTok employees reported receiving multiple threats, across various social media platforms, from 33-year-old Hawthorne resident Joseph Mayuyo. After an additional message … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • 3 signs that you need a new CPU instead of a GPU
  • The 3 PlayStation Plus games announced at State of Play you have to download to your PS5
  • 5 productivity apps that made my NAS more useful than Google Workspace
  • 6 tiny self-hosting tools that save me hours every week
  • 4 video game franchises that have lost their identity

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023