Researchers uncovered an exposed attacker-controlled server that revealed the full workflow behind a WebDAV phishing operation delivering malware through Windows shortcut and signed-binary execution chains. The infrastructure held 1,048 artifacts including phishing lures, testing notes, admin-panel files, delivery analytics, and documentation that suggested the operator used generative AI tooling to build content and test matrices at scale. The most active campaign impersonated Mexico’s CURP identity-record service through the typosquatted domain gobf[.]mx, used a WebDAV share on onedrive[.]cv, and abused CVE-2025-33053, a Windows working-directory hijack flaw previously linked to Stealth Falcon activity, to launch a disguised payload posing as a PDF report.
The recovered files showed the actor testing 59 .url shortcut variants against multiple signed Windows binaries, likely adapting after the original iediagcmd.exe technique became less effective on Windows 11 24H2. One infection chain delivered a fileless in-memory .NET infostealer that exfiltrated data to 77.110.127.205, while a second campaign, tracked as DlrtyGames, used a 7-Zip SFX dropper, DLL sideloading via a signed Ubisoft binary, IDAT-carried payloads, process hollowing, and persistence to deploy the modular PureRAT malware communicating with 23.94.252.228:57666. Delivery logs from the exposed Simba Service panel recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days, with activity heavily concentrated in Mexico.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Windows working-directory hijack vulnerability CVE-2025-33053 was patched by Microsoft in June 2025. Later reporting tied WebDAV-based malware delivery activity to this flaw.
Rapid7 reported two malware chains tied to the exposed infrastructure: a fake Mexican CURP identity-service lure delivering a fileless .NET infostealer via WebDAV, and a DlrtyGames chain using a 7-Zip SFX dropper, DLL sideloading, and process hollowing to deploy PureRAT. The findings also showed the actor testing 59 .url shortcut variants against signed Windows binaries to expand delivery options.
Rapid7 found an exposed attacker-controlled server containing 1,048 artifacts that revealed a full malware delivery and testing workflow rather than a simple payload host. The infrastructure exposed phishing lures, WebDAV delivery tests, ClickFix pages, LOLBin execution paths, CVE-based techniques, and signs of AI-assisted operator workflows.
Delivery telemetry from the exposed infrastructure showed concentrated campaign activity during June 20–26, 2026, with Mexico accounting for most traffic and launch activity. Logs recorded 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days.
Check Point Research published analysis connecting CVE-2025-33053 to Stealth Falcon and Horus in a Middle Eastern cyber-espionage context. This marks a public technical disclosure and attribution-related development around the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourcerapid7.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.