Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users

Campaign
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishing and payload-delivery risk. Delivery logs showed 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico accounting for 82.5% of traffic and 96.9% of launch activity. The lure flow used a search-ms: query and a disguised .scr file to open the operator's remote share, while the payload chain installed an infostealer in memory. The exposed toolkit also showed a broader testing pipeline, including alternate signed-binary hijack experiments and other delivery candidates.

Related Happenings

Mexico CURP lure .NET infostealer delivery

Malware Activity
H score21 First: 20.07.2026 20:29 Last: 20.07.2026 20:29 Sources 1

How related: It was an Inno Setup installer that unpacked a loader and ran a .NET infostealer entirely in memory, hollowed into a signed Qihoo 360 process.

About this happening: A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

DriveSurge large-scale website-hijack malware distribution campaign

Campaign
H score41 First: 02.06.2026 01:14 Last: 02.06.2026 01:14 Sources 1

About this happening: The DriveSurge campaign is redirecting visitors from thousands of compromised websites to malware-delivery infrastructure, creating a broad infection path through Cl...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign

Campaign
H score36 First: 26.05.2026 10:13 Last: 26.05.2026 10:13 Sources 1

About this happening: Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...

Timeline

  1. 20.07.2026 20:29 2 articles · 12h ago

    Rapid7 exposes an AI-assisted WebDAV phishing toolkit targeting Windows users in Mexico

    Initial Disclosure

    Rapid7 recovered 1,048 files from an exposed delivery server and found a live WebDAV-based phishing operation targeting Windows users in Mexico through gobf[.]mx, a CURP typosquat that used a fake record-retrieval page, a search-ms: launch, and an RTLO-disguised .scr lure to reach an infostealer payload. The recovered toolkit also showed broader testing around CVE-2025-33053, alternate signed-binary hijack candidates, and LLM-assisted workflow artifacts such as READMEs, lure-generation guides, matrix-style test write-ups, and a _MAPPING.csv linking test files to target binaries; delivery logs captured 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico driving most traffic and launch activity.

    Show sources