Horus Loader
Horus Loader is a custom multi-stage Windows loader used in 2025 espionage activity attributed by Check Point Research to Stealth Falcon (aka FruityArmor). It was observed in an infection chain exploiting the Windows WebDAV remote code execution zero-day CVE-2025-33053. The attacks used phishing-delivered .url shortcut files disguised as PDF documents; the shortcut set its working directory to an attacker-controlled WebDAV server and launched the legitimate Windows utility iediagcmd.exe, which was then induced to execute an attacker-supplied fake route.exe from the remote share. That fake route.exe installed Horus Loader.
Based on the reporting, Horus Loader is designed to be flexible and evasive. It is described as using code virtualization, anti-analysis techniques, string encryption, and control-flow flattening to hinder detection and reverse engineering. Its role in the chain is to clean up traces from earlier stages, bypass basic detection mechanisms, present a decoy PDF document to reduce user suspicion, and discreetly deploy or execute the final payload, Horus Agent.
The associated campaign targeted high-value government and defense organizations, with reported targeting in Turkey, Qatar, Egypt, and Yemen, and Stealth Falcon is described as a long-running espionage actor focused on political and strategic entities in the Middle East and Africa. Horus Loader was specifically linked to delivery of Horus Agent, a custom C++ implant built for the Mythic C2 framework. High-confidence behavioral context includes execution via attacker-hosted WebDAV infrastructure, use in a multi-stage loader chain, decoy document delivery, and final-stage deployment of Horus Agent.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...a multi-stage loader we called Horus Loader..."
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"This causes iediagcmd.exe to run the attacker's fake route.exe program from the remote server, which installs a custom multi-stage loader called 'Horus Loader.'"
Techniques & procedures
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniquesThe latest campaign from Stealth Falcon began with phishing emails. In one incident observed by Check Point, hackers targeted a Turkish defense organization...
Check Point uncovered the campaign after a victim uploaded the phishing email attachment to VirusTotal in March. On running the file, Check Point found the malicious file began to harvest diagnostic data and redirected the infected devices' WebDAV path to an attacker-controlled server.
Execution
2 techniquesMicrosoft patched a zero-day vulnerability in its web application framework exploited by an Emirati threat group... The flaw, tracked as CVE-2025-33053, is a remote code execution vulnerability in... WebDAV.
"Once the shortcut file was activated, it kicked off the next phase of the attack"
Stealth
4 techniques"Drop and open a decoy document to avoid suspicion"; "While the victim is occupied with viewing the decoy document"
On execution, it cleaned up previous utilities to evade detection and then deployed a decoy document and the final Horus Agent payload.
"abusing legitimate Windows tools... They tricked a built-in Windows utility into executing a malicious program"
Command and Control
1 techniqueOnce the connection was established, a malicious file named route.exe executed from the attacker's WebDAV server that deployed the Horus loader.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage loader used by Stealth Falcon, featuring code virtualization and anti-analysis techniques to evade detection and deliver payloads such as Horus Agent.
Custom multi-stage loader installed via a WebDAV-based execution technique (abusing CVE-2025-33053) that drops the primary payload (Horus Agent).
Loader component that displays a decoy PDF and executes the Horus Agent implant.
A multi-stage, evasive loader used to clean up infection artifacts, bypass basic detection, drop/open a decoy document, and discreetly deploy the final spyware/backdoor payload (Horus Agent).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.