Horus Loader is a custom multi-stage Windows loader used in 2025 espionage activity attributed by Check Point Research to Stealth Falcon (aka FruityArmor). It was observed in an infection chain exploiting the Windows WebDAV remote code execution zero-day CVE-2025-33053. The attacks used phishing-delivered .url shortcut files disguised as PDF documents; the shortcut set its working directory to an attacker-controlled WebDAV server and launched the legitimate Windows utility iediagcmd.exe, which was then induced to execute an attacker-supplied fake route.exe from the remote share. That fake route.exe installed Horus Loader.
Based on the reporting, Horus Loader is designed to be flexible and evasive. It is described as using code virtualization, anti-analysis techniques, string encryption, and control-flow flattening to hinder detection and reverse engineering. Its role in the chain is to clean up traces from earlier stages, bypass basic detection mechanisms, present a decoy PDF document to reduce user suspicion, and discreetly deploy or execute the final payload, Horus Agent.
The associated campaign targeted high-value government and defense organizations, with reported targeting in Turkey, Qatar, Egypt, and Yemen, and Stealth Falcon is described as a long-running espionage actor focused on political and strategic entities in the Middle East and Africa. Horus Loader was specifically linked to delivery of Horus Agent, a custom C++ implant built for the Mythic C2 framework. High-confidence behavioral context includes execution via attacker-hosted WebDAV infrastructure, use in a multi-stage loader chain, decoy document delivery, and final-stage deployment of Horus Agent.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...a multi-stage loader we called Horus Loader..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"This causes iediagcmd.exe to run the attacker's fake route.exe program from the remote server, which installs a custom multi-stage loader called 'Horus Loader.'"
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The latest campaign from Stealth Falcon began with phishing emails. In one incident observed by Check Point, hackers targeted a Turkish defense organization...
Check Point uncovered the campaign after a victim uploaded the phishing email attachment to VirusTotal in March. On running the file, Check Point found the malicious file began to harvest diagnostic data and redirected the infected devices' WebDAV path to an attacker-controlled server.
"Drop and open a decoy document to avoid suspicion"; "While the victim is occupied with viewing the decoy document"
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage loader used by Stealth Falcon, featuring code virtualization and anti-analysis techniques to evade detection and deliver payloads such as Horus Agent.
Custom multi-stage loader installed via a WebDAV-based execution technique (abusing CVE-2025-33053) that drops the primary payload (Horus Agent).
Loader component that displays a decoy PDF and executes the Horus Agent implant.
A multi-stage, evasive loader used to clean up infection artifacts, bypass basic detection, drop/open a decoy document, and discreetly deploy the final spyware/backdoor payload (Horus Agent).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.