bookmarkscope.com

  • Trending Stories
  • Submit Story
  • Login
Trending now

Luxury Transportation in Aspen | Corporate & Private Car Service

ADP HR Services

SPARK Matrix™: Unified Retail Commerce Platform

SPARK Matrix™: Data Preparation Tools

Training Management Solutions

How to Launch a Startup Website for Free – and Actually Get Signups Before You ...

SPARK Matrix™: Enterprise Information Archiving

Russian APT abuses Windows Hyper-V for persistence and malware execution

1
technologyscope technologyscope 6 months ago in Technology 0

Reliable. Secure. Since 2012. Exchange Crypto Sign up to get a trading fee discount!


[ad_1]

The attackers then used the Import-VM and Start-VM PowerShell cmdlets to import the virtual machine into Hyper-V and start it with the name WSL — a deception tactic given that WSL on Windows stands for Windows Subsystem for Linux, another feature that allows running Linux containers under the Windows kernel. More popular than Hyper-V for virtualization on Windows, WSL is widely used by developers, making its presence less likely to receive scrutiny.

The Alpine Linux VM is very small and hosts only two custom implants that Bitdefender has dubbed CurlyShell and CurlCat. They are both built using libcurl, an open-source network transfer library that supports a large variety of protocols.

CurlyShell uses libcurl to connect to a command-and-control (C2) server and set up a reverse shell, meaning it listens for commands issued by the server, passes them to the Linux command line, and returns the output. Meanwhile, CurlCat acts as a proxy for tunneling SSH traffic as HTTP requests, making that traffic harder to detect by network monitoring tools.

[ad_2]
https://www.csoonline.com/article/4085272/russian-apt-abuses-windows-hyper-v-for-persistence-and-malware-execution.html

  • Facebook
  • Twitter
  • Pinterest
Report Story

Related Stories

  1. ADP HR Services
  2. SPARK Matrix™: Data Preparation Tools
  3. Training Management Solutions
  4. SPARK Matrix™: Enterprise Information Archiving
Tags : abuses, APT, Execution, HyperV, malware, persistence, Russian, Windows

Categories

  • Automotive
  • Business
    • Real Estate
  • Education
  • Health & Fitness
  • News
  • Science
  • Shopping
  • Sports & Outdoors
  • Technology
  • Travel

Trending Tags

  • Technology
  • IT
  • #Business
  • Artificial intelligence
  • Analytics
  • Management
  • AI
  • real estate
  • #Marketing
  • AI Development Software Development Services
  • ai services
  • news
  • Education
  • cybersecurity
  • security
  • BookmarkScope – Social Bookmarking
  • Privacy Policy
  • Content Policy
  • Contact
Copyright bookmarkscope.com 2026. All Rights Reserved
Login Register

Login

Lost Password

Register

Lost Password