Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection

Nov 6, 2025

The threat actor known as Curly COMrades has been observed exploiting virtualization technologies as a way to bypass security solutions and execute custom malware.
According to a new report from Bitdefender, the adversary is said to have enabled the Hyper-V role on selected victim systems to deploy a minimalistic, Alpine Linux-based virtual machine.
“This hidden environment, with its lightweight

Get Free Report & Network Analysis

Please check your email for the free report.