Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Windows users in Mexico
Incident: A malware campaign leveraging AI-assisted phishing and WebDAV hijacks to deliver infostealers.
Impact: Unauthorized execution of malicious code and potential theft of sensitive user data.
Attacker: Unidentified Russian-speaking threat actors
Analysis: The campaign utilizes a WebDAV working-directory hijack to bypass security warnings and execute malicious payloads via signed Windows binaries. Evidence suggests the operator used LLMs to automate the creation of lures and the systematic testing of dozens of LOLBAS binaries. The operation specifically targeted Mexican government ID services to deliver infostealers.
Recommendations: Patch CVE-2025-33053 and related MSHTML/NTLM vulnerabilities immediately.; Monitor for unusual WebDAV traffic and the execution of signed binaries from remote shares.; Implement strict controls on .url shortcut files and monitor for AI-generated phishing patterns.
Source: The Hacker News / Rapid7
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source