Listen to this Post

Covert Cyber Threat Emerges in Eastern Europe
A stealthy cyber-espionage group, dubbed Curly COMrades, has surfaced with a sophisticated new malware known as MucorAgent, designed to maintain long-term access to targeted systems through an unusual persistence method. First identified in mid-2024, the group has been linked to operations that align with Russian geopolitical interests, specifically targeting government and judicial institutions in Georgia and energy companies in Moldova. While no direct ties to known Russian APTs have been confirmed, researchers suggest the campaign’s objectives fit within the Kremlin’s strategic agenda.
MucorAgent is a custom-built .NET-based backdoor with a three-stage attack process. It begins by executing AES-encrypted PowerShell scripts, then uploads the results to a command-and-control (C2) server. This stealthy approach is further enhanced by the attackers’ heavy use of curl.exe for data exfiltration and the hijacking of Component Object Model (COM) objects. The group also deploys proxy tools like the Go-based Resocks, which are installed as scheduled tasks or Windows services to ensure persistence, while also setting up custom SOCKS5 servers and tunneling traffic through SSH + Stunnel.
Their persistence mechanism stands out for its unpredictability — by hijacking CLSIDs tied to the Native Image Generator (NGEN) in Windows, they create a scheduled task that appears inactive but is triggered at irregular intervals, often during idle system states or application installations. This erratic behavior is likely complemented by secondary, more predictable methods.
The MucorAgent payloads are capable of bypassing Windows Antimalware Scan Interface (AMSI) and retrieving encrypted scripts disguised as .png files from compromised sites. The group actively hunts for credentials, attempting NTDS database extractions, LSASS memory dumps, and using living-off-the-land binaries (LOLBins) like netstat, wmic, and PowerShell commands for network reconnaissance. They also install legitimate remote monitoring tools such as Remote Utilities (RuRat) and commercial RMM software to blend into normal IT workflows.
Despite their advanced tradecraft, Curly COMrades have not gone undetected. Modern EDR and XDR platforms have picked up on anomalies in their activity, indicating that even sophisticated state-aligned groups can leave traces when operating at scale.
What Undercode Say:
The Curly COMrades case illustrates the evolving nature of cyber-espionage in a geopolitical context where cyber operations increasingly replace traditional intelligence gathering. MucorAgent is not just another malicious program; it is a multi-layered espionage platform designed to evade detection while allowing deep penetration into critical networks.
The most striking element is the use of a dormant-looking scheduled task tied to NGEN, which cleverly exploits Windows’ internal behaviors for persistence. Unlike typical backdoors that rely on predictable triggers, this method injects an element of randomness, making it harder for defenders to simulate or replicate for detection testing. This persistence design also highlights how attackers increasingly abuse native system features instead of introducing foreign code that might be flagged.
The deployment of multiple fallback channels — from SOCKS5 servers to CurlCat traffic obfuscation — indicates an obsession with redundancy. This redundancy ensures operations continue even if one method is shut down, a tactic commonly seen in state-sponsored intrusions.
Credential harvesting is another clear indicator of long-term espionage goals. By targeting NTDS databases and LSASS memory, the group is not just after one-time access but is instead attempting to map entire organizational trust relationships for extended campaigns.
Another telling sign of sophistication is the blending of malicious and legitimate tools. By using widely recognized IT utilities like RuRat or commercial RMM software, the attackers camouflage their activity inside the noise of normal IT administration. This approach makes forensic attribution harder, especially in organizations without robust internal monitoring.
However, while the Curly COMrades are skilled, their campaign also demonstrates the limits of stealth in the modern cybersecurity landscape. The noise generated by large-scale credential dumping, the use of multiple C2 communications, and the movement of data through compromised public websites eventually triggered alerts. This aligns with a growing trend — no matter how well-resourced a threat actor is, persistence at scale is inherently noisy.
From a defensive standpoint, this case reinforces the need for behavior-based detection rather than reliance on static indicators. Organizations in politically sensitive sectors, especially those in Eastern Europe, should expect similar campaigns and invest in both endpoint telemetry and anomaly-based monitoring. Additionally, the use of seemingly harmless image files to deliver encrypted payloads underscores the importance of deep content inspection rather than trusting file extensions.
Curly COMrades’ operations may not yet have achieved the same infamy as APT28 or Sandworm, but their tactics show a blend of innovation and discipline that suggests a long-term presence on the espionage stage.
🔍 Fact Checker Results:
✅ Curly COMrades is a newly identified cyber-espionage group active since mid-2024.
✅ MucorAgent is a custom .NET backdoor with three operational stages.
✅ Targets include Georgian government and judicial bodies, and Moldovan energy firms.
📊 Prediction:
Given their operational sophistication and alignment with Russian interests, Curly COMrades is likely to expand operations into other Eastern European and possibly Western European states within the next 12 months. Future variants of MucorAgent may incorporate more predictable persistence mechanisms for reliability while retaining stealth capabilities, and their credential-harvesting focus suggests an aim to build long-term espionage infrastructures across multiple sectors.
If you want, I can now also optimize this with keyword-focused SEO structuring so it ranks higher in cybersecurity search queries. Would you like me to proceed with that?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




