🚨Threat Campaign Alert: Curly COMrades APT Targets Georgia & Moldova’s Government and Energy Sectors Using MucorAgent Backdoor & Proxy Tools🚨
Summary: A newly discovered Russia-aligned APT, Curly COMrades, is targeting Georgian government/judicial bodies and a Moldovan energy firm. They deploy the custom MucorAgent backdoor and proxy tools like Resocks, SOCKS5, SSH, and Stunnel. Compromised websites are used for covert C2 communications and data exfiltration.
Threat Actor/Threat Group: Curly COMrades
Malware: MucorAgent, RuRat
Targeted Countries: Georgia, Moldova
Targeted Industries: Government, Energy Distribution
Targeted Applications/CVE: Not mentioned
Impact: Credential theft, long-term network access, espionage, data exfiltration
IOC:
IP
75[.]127[.]13[.]136,
207[.]180[.]194[.]109,
91[.]107[.]174[.]190,
96[.]30[.]124[.]103,
45[.]43[.]91[.]10,
194[.]87[.]31[.]171,
MD5
44a57a7c388af4d96771ab23e85b7f1e,
2d007c5bd0b84ca9c9b4c6b4c17bd997,
2f6bc7f137c689add399402e485aa604,
e5a7d0df12094e9db90242092891b10e,
5ed6b17103b231e9ff2abda1094083e3,
MITRE TTP IDs:
T1078:Valid Accounts, T1059.003:Command and Scripting Interpreter - Windows Command Shell, T1059.005:Command and Scripting Interpreter - Visual Basic, T1105:Ingress Tool Transfer, T1090.003:Proxy - Multi-hop Proxy, T1572:Protocol Tunneling, T1071.001:Application Layer Protocol - Web Protocols, T1071.004:Application Layer Protocol - DNS, T1027:Obfuscated Files or Information, T1560.001:Archive Collected Data - Archive via Utility, T1041:Exfiltration Over C2 Channel, T1573.001:Encrypted Channel - Symmetric Cryptography, T1053.005:Scheduled Task/Job - Scheduled Task, T1547.001:Boot or Logon Autostart Execution - Registry Run Keys/Startup Folder, T1562.001:Impair Defenses - Disable or Modify Tools, T1036.005:Masquerading - Match Legitimate Name or Location
----------------------------------------------------------------------------------------------
🚀Join us on our mission to secure the digital world and make cyber defense affordable to everyone! 🌐 Follow "CyberXTron Technologies" for the timely, relevant and actionable cyber threat insights.
#CurlyCOMrades #MucorAgent #CyberEspionage #APT #GeopoliticalCyberThreats #CredentialTheft #BackdoorMalware #ProxyTools #C2Infrastructure #CyberSecurity #GeorgiaCyberAttack #ThreatIntelligence #cyberXTron #uncovertheunknown🛡️