Curly COMrades Georgia and Moldova cyber espionage campaign
Campaign
Summary
Hide ▲
Show ▼
The Curly COMrades espionage operation has expanded against entities in Georgia and Moldova, raising the risk of long-term network access and credential theft. The group is using MucorAgent, Ngen COM hijacking, and legitimate tools to blend into normal activity. The campaign matters because it is built for reconnaissance, persistence, and exfiltration rather than a one-time intrusion. The activity has been tracked since mid-2024, with evidence of MucorAgent use dating back to November 2023.
Related Happenings
Mustang Panda multi-country espionage campaign against government and telecom targets
Campaign
H score37
First: 28.01.2026 13:40
Last: 28.01.2026 13:40
Sources 1
About this happening:
Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
Mustang Panda multi-country espionage campaign against government and telecom targets
CampaignAbout this happening: Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
Coldriver intensified high-profile espionage campaign
Campaign
H score37
First: 21.10.2025 13:02
Last: 21.10.2025 13:02
Sources 1
About this happening:
In October 2025, GTIG said Coldriver — also tracked as Star Blizzard, Callisto and UNC4057 — had moved from LostKeys to a new chain built around NoRo...
Coldriver intensified high-profile espionage campaign
CampaignAbout this happening: In October 2025, GTIG said Coldriver — also tracked as Star Blizzard, Callisto and UNC4057 — had moved from LostKeys to a new chain built around NoRo...
Latest development: 03.12.2025 18:45
Star Blizzard, also known as ColdRiver or Calisto, was identified in a fresh spear-phishing wave against Reporters Without Borders (RSF) and another organization. The operators used impersonated trusted contacts, a custom Adversary-in-the-Middle (AiTM) kit on account.simpleasip[.]org, modified ProtonMail interface elements, and attacker-controlled API handling for CAPTCHA and two-factor authentication (2FA) to harvest credentials.
Confucius Pakistan phishing campaign using WooperStealer and Anondoor
Campaign
H score32
First: 02.10.2025 17:44
Last: 02.10.2025 17:44
Sources 1
About this happening:
Confucius is running an active phishing campaign against Pakistan that uses WooperStealer and Anondoor, expanding the risk of credential theft and device compr...
Confucius Pakistan phishing campaign using WooperStealer and Anondoor
CampaignAbout this happening: Confucius is running an active phishing campaign against Pakistan that uses WooperStealer and Anondoor, expanding the risk of credential theft and device compr...
Gamaredon and Turla coordinated Ukraine compromise campaign
Campaign
H score34
First: 19.09.2025 11:24
Last: 19.09.2025 11:24
Sources 1
About this happening:
The Gamaredon-Turla collaboration has been tied to a multi-stage campaign against Ukrainian entities, expanding Russian access inside the country. In February, April...
Gamaredon and Turla coordinated Ukraine compromise campaign
CampaignAbout this happening: The Gamaredon-Turla collaboration has been tied to a multi-stage campaign against Ukrainian entities, expanding Russian access inside the country. In February, April...
Noisy Bear Kazakhstan oil and gas phishing campaign
Campaign
H score32
First: 11.09.2025 15:00
Last: 11.09.2025 15:00
Sources 1
About this happening:
The Noisy Bear operation is conducting phishing-based intrusion activity against Kazakhstan's oil and gas sector, creating espionage risk for KazMunayGas and relat...
Noisy Bear Kazakhstan oil and gas phishing campaign
CampaignAbout this happening: The Noisy Bear operation is conducting phishing-based intrusion activity against Kazakhstan's oil and gas sector, creating espionage risk for KazMunayGas and relat...
Timeline
-
12.08.2025 16:00 1 articles · 11mo ago
Curly COMrades targets Georgia and Moldova
Initial DisclosureA previously undocumented threat actor dubbed Curly COMrades was observed targeting judicial and government bodies in Georgia and an energy distribution company in Moldova for long-term access, using MucorAgent, Ngen COM hijacking, Resocks, SSH, Stunnel, SOCKS5, CurlCat, RuRat, and Mimikatz to support credential theft, reconnaissance, and exfiltration.
Show sources
- New ‘Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks — thehackernews.com — 12.08.2025 16:00