The Containment Era is here. →Explore

Executive Summary

In October 2025, the advanced persistent threat group Curly COMrades launched a sophisticated attack campaign exploiting Windows Hyper-V virtualization to evade endpoint detection and response (EDR) solutions. By covertly enabling Hyper-V on targeted systems, attackers deployed a minimal Alpine Linux-based virtual machine (VM) hidden within Windows hosts. This VM served as an isolated enclave to execute custom malware and facilitate command-and-control activities, significantly complicating detection and forensics for defenders. Victims experienced unauthorized data access and increased potential for lateral movement, while standard EDR tools failed to monitor the malicious payloads running inside the guest VM.

This attack highlights a growing trend of leveraging virtualization and container technologies to bypass security controls. As organizations increasingly adopt hybrid and multi-cloud environments, adversaries are developing novel methods to mask malicious operations from traditional detection mechanisms, underscoring the need for advanced visibility and zero trust segmentation.

Why This Matters Now

The exploitation of virtualization platforms for stealthy attacks is escalating, posing urgent challenges for defending modern cloud and hybrid infrastructures. Without enhanced east-west traffic monitoring and identity-based segmentation, organizations remain vulnerable to evasive tactics that render traditional endpoint security ineffective.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

They leveraged Hyper-V to run a hidden Alpine Linux VM within Windows hosts, executing malware outside the EDR’s visibility scope.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust controls such as segmentation, internal traffic inspection, strong egress policy, and east-west visibility would have significantly limited the attack by containing VM lateral movement, detecting anomalous traffic, and preventing covert data exfiltration. Policy-based enforcement would block unauthorized workloads even when attackers attempt to evade endpoint detection.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Would have provided early detection and alerting of unauthorized or suspicious remote access attempts.

Privilege Escalation

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline policy enforcement would detect and control unauthorized workload instantiation and privilege escalation.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Microsegmentation prevents lateral movement between workloads, blocking access from rogue VMs.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound filtering and FQDN controls disrupt unapproved communication to C2 infrastructure.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Line rate encryption and data in transit protections prevent cleartext exfiltration and enable visibility into anomalous flows.

Impact (Mitigations)

Behavioral baselining and alerting identify ransomware actions and unauthorized workload behavior.

Impact at a Glance

Affected Business Functions

  • IT Operations
  • Security Monitoring
  • Network Management
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive government and corporate data due to unauthorized remote access and data exfiltration.

Recommended Actions

  • Deploy microsegmentation and Zero Trust segmentation to contain lateral movement from rogue or hidden workloads.
  • Enforce strict egress controls, including FQDN and application-based filtering, to detect and prevent covert command and control or data exfiltration attempts.
  • Extend centralized visibility and policy management across all cloud, on-prem, and hybrid environments for unified incident detection.
  • Implement real-time traffic anomaly and behavior monitoring to quickly identify VM-level persistence and evasion tactics.
  • Automate incident response playbooks leveraging Cloud Native Security Fabric to detect, contain, and remediate hidden infrastructure attacks.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image