The record
Written from the 1 report below. Nothing here is unsourced.
- Rapid7 obtained a malware operator's entire development toolkit from an exposed server, revealing two phishing delivery chains, one actively targeting Mexican users through a fake government CURP ID-lookup site that delivered an infostealer via WebDAV.
- The materials show the operator testing a WebDAV working-directory hijack tied to CVE-2025-33053, which Microsoft patched in June 2025, and building a kit of 59 alternative signed Windows binaries to try the same technique because the original path no longer works on Windows 11 24H2.
- Rapid7 reads the templated documentation and notes as signs the operator used generative AI, likely with help from the open-source coding agent CodeRRR, to build and document the operation at speed.
- Over five and a half days the delivery panel logged more than 77,000 requests from 101 countries, with Mexico accounting for most launch activity, though actual infection counts cannot be confirmed.
What to watch next
- Whether operators weaponize the 59 alternative signed binaries in the test kit, since the patched iediagcmd.exe path is closed
- Expanded or new campaigns using the CVE-2025-33053 WebDAV working-directory hijack technique
- Detection of the behavioral signs Rapid7 flagged: WebClient service activation, WebDAV/UNC child process paths, and right-to-left override filenames
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Mexican Users / Crypto Investors credential harvest· immediate
- Microsoft Windows Ecosystem software vulnerability· days
- Corporate Infrastructure malware infection· immediate
Coverage1
1 report
English national1
Filed from India ×3, United States ×1
Named Mexico · Russia · United States · Germany · Cert-mx · Check Point · Coderrr · Internet Explorer · Microsoft · PureRAT · Qihoo 360 · Rapid7 · Simba Service · Stealth Falcon · Ubisoft
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
