Skip to main content
Mallory
MalwareUsed by 1 actor

MucorAgent

MucorAgent is a bespoke modular three-stage .NET backdoor used by the threat actor Curly COMrades in cyberespionage operations assessed to align with Russian geopolitical interests. Reporting places its use from at least November 2023, with campaigns observed targeting judicial and government bodies in Georgia and an energy distribution company in Moldova, and more broadly Eastern European organizations.

Its key capability is stealthy persistent access on Windows systems through COM/CLSID hijacking tied to .NET Native Image Generator (NGEN) execution. Observed persistence abused NGEN-related scheduled task execution and ran under SYSTEM, including hijacking CLSID {de434264-8fe9-4c0b-a83b-89ebeebff78e} associated with the scheduled task ".NET Framework NGEN v4.0.30319 Critical" and COM handler hijacking of CLSID {613fba38-a3df-4ab8-9674-5604984a299a} (NGenTaskLauncher.CriticalTaskHandler64). The malware has been described as leveraging a dormant or seemingly inactive NGEN scheduled task for persistence.

MucorAgent can execute AES-encrypted PowerShell payloads via the System.Management.Automation namespace without launching powershell.exe, apply an AMSI bypass, and upload execution results to command-and-control infrastructure. Encrypted payloads were reported as disguised as PNG data, with exfiltration performed via curl.exe and in some cases routed through compromised legitimate websites used as relays for C2 and data theft. Potential MucorAgent-related C2 infrastructure mentioned in the reporting includes IP address 45.43.91[.]10 and an additional .org domain not fully specified in the source content.

The malware was deployed as part of broader intrusion activity focused on long-term access, credential theft, lateral movement, and collection. Associated operator behavior included repeated attempts to extract NTDS.dit, dump LSASS memory, and perform DCSync, using tooling such as Mimikatz, comsvcs.dll abuse, procdump, Volume Shadow Copy NTDS extraction, and custom or adapted LSASS dump tools. Supporting tradecraft around MucorAgent operations included use of Resocks, SOCKS5 tooling, SSH remote port forwarding, Stunnel, and Remote Utilities (RuRat), with staged data commonly placed in C:\Users\Public\Documents before archiving and exfiltration.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Curly COMrades

...known to use a custom three-stage .NET backdoor dubbed ‘MucorAgent’, which is capable of executing AES-encrypted PowerShell scripts and uploading results to a command and control (C2) server.

via sentinelone blogsentinelone.com
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Nov 6, 2025
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

MucorAgent is a modular .NET implant used by Curly COMrades, with early versions dating to November 2023.

Read more
sentinelone blogNews
Aug 15, 2025
The Good, the Bad and the Ugly in Cybersecurity – Week 33

Custom three-stage .NET backdoor used for cyberespionage, supporting encrypted PowerShell execution, C2 communications/exfiltration (via curl.exe), persistence via COM/CLSID hijacking, AMSI bypass, payload retrieval disguised as PNGs, credential theft (NTDS extraction attempts, LSASS dumping), and in-memory execution to evade detection.

Read more
scworldNews
Aug 13, 2025
New MucorAgent malware leveraged in Eastern Europe-targeted campaign

MucorAgent is a novel backdoor used for cyberespionage, enabling prolonged persistence by abusing a dormant scheduled task within the NGEN component of Windows. It is deployed after attackers establish concealed pathways using Stunnel and Resocks, and is used in conjunction with credential theft tools like Mimikatz and DCSync.

Read more
hackreadNews
Aug 12, 2025
Russian-Linked Curly COMrades Deploy MucorAgent Malware in Europe

MucorAgent is a backdoor malware used by the Russian-linked Curly COMrades group to maintain persistent access to compromised systems. It hijacks the Windows NGEN component by exploiting a dormant scheduled task, allowing it to reactivate at unpredictable times and evade detection. The malware is used for espionage and data theft, particularly targeting government and energy sectors in Eastern Europe.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.