Researchers have discovered that the Curly COMrades threat group used Alpine Linux virtual machines on Windows hosts to hide custom malware and evade detection. The VM design routed all malicious traffic through the host IP, making conventional EDR tools ineffective and allowing targeted intrusions in Georgia and Moldova to continue unnoticed.

