Skip to main content
Mallory
MalwareUsed by 2 actors

CurlCat

CurlCat is a custom ELF malware implant used by the Curly COMrades espionage cluster, which Bitdefender assesses as aligned with Russian geopolitical interests. It is a libcurl-based companion implant to CurlyShell and is primarily used for traffic tunneling rather than command execution. Multiple reports describe it as a netcat-like reverse proxy or relay that facilitates bidirectional data transfer between STDIN/STDOUT and a command-and-control server over HTTPS, and as a payload used to manage SSH reverse proxy tunnels.

In the observed tradecraft, CurlCat was deployed inside a lightweight Alpine Linux virtual machine imported onto compromised Windows 10 systems through abuse of Microsoft Hyper-V. The VM used Hyper-V Default Switch/NAT so outbound traffic appeared to originate from the victim host IP, helping evade host-based EDR visibility. CurlCat was located at /root/updater in the VM, had MD5 1a6803d9a2110f86bb26fcfda3606302, and did not maintain persistence itself; instead, it was launched on demand via the CurlyShell channel. The malware wrapped outgoing SSH traffic into standard HTTP request payloads, allowing covert tunneling through compromised legitimate websites used as relays/proxies. Investigators also noted that the sample was configured to disable TLS certificate verification, enabling arbitrary certificates on relay servers.

CurlCat and CurlyShell share a largely identical C++ code base built around libcurl, but differ in handling received data: CurlyShell executes commands directly, while CurlCat funnels traffic through SSH. The malware used a custom Base64 substitution alphabet/non-standard Base64 encoding for evasion. Reporting links CurlCat to operations targeting judicial and government entities in Georgia and an energy distribution company in Moldova, and more broadly to post-compromise host-based tradecraft associated with Curly COMrades.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Curly COMrades

The two custom implants deployed in the VM are ELF binaries based on libcurl and are used for command execution and traffic tunneling: CurlyShell … CurlCat – Companion tool used when tunneling is needed…

via bleeping computerbleepingcomputer.com
Sandworm

Bitdefender’s reporting : Post-compromise host-based tradecraft (Hyper-V abuse for EDR evasion, custom implants CurlyShell/CurlCat)

via aws security blogaws.amazon.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Other

1 technique
T1562Impair DefensesEvidence1

Bitdefender’s reporting : Post-compromise host-based tradecraft (Hyper-V abuse for EDR evasion, custom implants CurlyShell/CurlCat)

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.