Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users
Campaign
Summary
Hide ▲
Show ▼
The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishing and payload-delivery risk. Delivery logs showed 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico accounting for 82.5% of traffic and 96.9% of launch activity. The lure flow used a search-ms: query and a disguised .scr file to open the operator's remote share, while the payload chain installed an infostealer in memory. The exposed toolkit also showed a broader testing pipeline, including alternate signed-binary hijack experiments and other delivery candidates.
Related Happenings
Mexico CURP lure .NET infostealer delivery
Malware Activity
H score21
First: 20.07.2026 20:29
Last: 20.07.2026 20:29
Sources 1
How related:
It was an Inno Setup installer that unpacked a loader and ran a .NET infostealer entirely in memory, hollowed into a signed Qihoo 360 process.
About this happening:
A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...
Mexico CURP lure .NET infostealer delivery
Malware ActivityHow related: It was an Inno Setup installer that unpacked a loader and ran a .NET infostealer entirely in memory, hollowed into a signed Qihoo 360 process.
About this happening: A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
DriveSurge large-scale website-hijack malware distribution campaign
Campaign
H score41
First: 02.06.2026 01:14
Last: 02.06.2026 01:14
Sources 1
About this happening:
The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
DriveSurge large-scale website-hijack malware distribution campaign
CampaignAbout this happening: The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign
Campaign
H score36
First: 26.05.2026 10:13
Last: 26.05.2026 10:13
Sources 1
About this happening:
Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...
Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign
CampaignAbout this happening: Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...
Timeline
-
20.07.2026 20:29 2 articles · 12h ago
Rapid7 exposes an AI-assisted WebDAV phishing toolkit targeting Windows users in Mexico
Initial DisclosureRapid7 recovered 1,048 files from an exposed delivery server and found a live WebDAV-based phishing operation targeting Windows users in Mexico through gobf[.]mx, a CURP typosquat that used a fake record-retrieval page, a search-ms: launch, and an RTLO-disguised .scr lure to reach an infostealer payload. The recovered toolkit also showed broader testing around CVE-2025-33053, alternate signed-binary hijack candidates, and LLM-assisted workflow artifacts such as READMEs, lure-generation guides, matrix-style test write-ups, and a _MAPPING.csv linking test files to target binaries; delivery logs captured 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico driving most traffic and launch activity.
Show sources
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — thehackernews.com — 20.07.2026 20:29
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — thehackernews.com — 20.07.2026 20:29