Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053) — Threadlinqs Intelligence
As of 2026-07-21, Exposed Server Reveals AI-Assisted WebDAV Phishing Kit Targeting Mexican Users (CVE-2025-33053) is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 46 indicators of compromise.
Threat ID: TL-2026-1566 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-21 · revalidated 1× · latest source
Rapid7 obtained 1,048 files from an exposed Russian-speaking phishing operator's 'Simba Service' delivery server, revealing a WebDAV working-directory-hijack toolkit (CVE-2025-33053) built and
In late June 2026, Rapid7 researchers gained access to an exposed operator server hosting an admin panel dubbed 'Simba Service' (default port and default credentials left unchanged), along with 1,048 files comprising lure templates, filename-spoofing experiments, execution tests, droppers, builder notes, and two live delivery chains. Evidence embedded in the files — hardcoded local paths to an open-source AI coding agent nicknamed 'Coderrr' (design cues drawn from Claude Code, GitHub Copilot CLI, and Cursor), templated/emoji-heavy LLM-style documentation, and casual folder names such as 'testik' — points to an operator using generative AI to accelerate development, testing, and documentation of a WebDAV-based malware-delivery kit.
The most mature and heavily tested exploit in the kit is CVE-2025-33053 (CVSS 8.8), a WebDAV working-directory-hijack remote code execution flaw (CWE-73, External Control of File Name or Path) patched by Microsoft in June 2025 and added to the CISA KEV catalog with a July 1, 2025 remediation deadline due to active exploitation by the UAE-linked APT group Stealth Falcon (observed March 2025 against a Turkish defense organization delivering the 'Horus Agent' backdoor via a PDF-themed .url shortcut). In this operator's kit, a malicious `.url` Internet Shortcut file sets its working directory to an attacker-controlled WebDAV share; when the shortcut launches a signed Microsoft utility such as `iediagcmd.exe` (Internet Explorer diagnostics) or `CustomShellHost.exe`, Windows' DLL/binary search-order and `Process.Start()` resolution load the attacker's file (e.g., a rogue `route.exe`) from the remote WebDAV path instead of the legitimate System32 binary — executing with no SmartScreen or Mark-of-the-Web warning. The operator's own notes claim 'WITHOUT any security warnings. Zero alerts!' The technique fails on Windows 11 24H2 because Internet Explorer components were removed from that build.
The kit's testing arsenal contains 59 candidate `.url` files targeting different signed/LOLBAS binaries (.NET tools including InstallUtil and RegAsm, UAC-bypass candidates, and other Living-Off-the-Land binaries), evidencing systematic experimentation to find the most reliable and stealthy hijack target. Two secondary vulnerabilities were also tested for inclusion: CVE-2026-21513, an MSHTML/`ieframe.dll` security-feature-bypass flaw (CVSS 8.8) that lets attacker-controlled hyperlink navigation reach `ShellExecuteExW` and execute local/remote resources outside the browser sandbox (exploited in the wild by APT28 before its February 2026 patch); and CVE-2025-24054, an NTLM hash-disclosure/spoofing flaw in Windows Explorer's handling of `.library-ms` files with UNC paths, which triggers an SMB/NTLMv2 authentication leak merely by a user right-clicking or navigating to a folder containing the crafted file (actively exploited since March 2025 against Polish and Romanian government/private targets).
The live, production campaign observed by Rapid7 impersonated Mexico's CURP (Clave Única de Registro de Población) national-ID lookup portal via the typosquat domain gobf[.]mx. Over June 20–26, 2026 the lure generated 77,098 requests from 3,892 unique IPs across 101 countries, with 82.5% of traffic and 96.9% of launch/execution events (2,384 of 2,441 recorded launches, ~97.7%) originating from Mexico and clustering during Mexican working hours — consistent with genuine victim traffic rather than automated scanning; secondary US/Germany traffic appeared to be researcher or automated reconnaissance. Delivery volume dropped sharply after June 24, 2026.
Victims who reached the lure were served a file whose name was obfuscated with a right-to-left-override control character (U+202E) to visually display as a PDF while the underlying extension was a Windows `.scr` screensaver executable — a classic RTLO double-extension spoof. Execution ran an Inno Setup installer (`.scr`) that unpacked a loader, which in turn ran a .NET infostealer e
Weaknesses (CWE)
CWE-73, CWE-668, CWE-522, CWE-254, CWE-706
Target sectors: government administration, individuals consumers, finance, cryptocurrency
Target regions: mexico, North America
Related threats
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)
- ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software Sites
- Operation Turb00: Multi-Stage HijackLoader (IDAT Loader) Campaign Delivers Vidar v2.1 Infostealer and SnappyClient RAT via PNG-IDAT Steganography
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malware
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader, StealC, Remus Stealer, Amatera Stealer, CastleLoader, NetSupport RAT, ResiLoader)
- Steam Workshop Abused to Distribute Malware via Wallpaper Engine (DarkKomet, Lumma, Vidar, RenEngine)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 46 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2025-33053, CVE-2026-21513, CVE-2025-24054, T1566, T1566.002, T1190, T1204, T1204.002, T1047, T1203, T1505, T1068, T1548.002