Mexico CURP lure .NET infostealer delivery
Malware Activity
Summary
Hide ▲
Show ▼
A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived through an Inno Setup installer that unpacked a loader and ran in memory inside a signed Qihoo 360 process. It stole cryptocurrency wallets, browser credentials, session cookies, and Telegram sessions. Live delivery telemetry showed 2,441 launch events over about 5.5 days, with Mexico driving most observed activity.
Related Happenings
Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users
Campaign
H score25
First: 20.07.2026 20:29
Last: 20.07.2026 20:29
Sources 1
How related:
Over roughly 5.5 days (June 20 to 26, 2026 UTC), the delivery panel logged 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico alone driving 82.5% of traffic and 96.9% of launch activity.
About this happening:
The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishi...
Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users
CampaignHow related: Over roughly 5.5 days (June 20 to 26, 2026 UTC), the delivery panel logged 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico alone driving 82.5% of traffic and 96.9% of launch activity.
About this happening: The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishi...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
Campaign
H score33
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
CampaignAbout this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
Konni blockchain developer targeting campaign with AI-generated PowerShell malware
Campaign
H score33
First: 24.01.2026 17:23
Last: 24.01.2026 17:23
Sources 1
About this happening:
Konni (Opal Sleet, TA406) is running an active campaign that uses AI-generated PowerShell malware to target developers and engineers in the blockchain sector, with...
Konni blockchain developer targeting campaign with AI-generated PowerShell malware
CampaignAbout this happening: Konni (Opal Sleet, TA406) is running an active campaign that uses AI-generated PowerShell malware to target developers and engineers in the blockchain sector, with...
Timeline
-
20.07.2026 20:29 2 articles · 12h ago
WebDAV infostealer campaign hits Windows users in Mexico
Victim Impact UpdateA fake CURP record-lookup lure at gobf[.]mx sent Windows users into a WebDAV share and delivered a disguised .scr payload that unpacked a loader and ran a .NET infostealer in memory inside a signed Qihoo 360 process. Rapid7 says Mexico drove most of the observed traffic and launch activity during the short-lived delivery burst, which the panel tracked over roughly 5.5 days in late June 2026.
Show sources
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — thehackernews.com — 20.07.2026 20:29
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — thehackernews.com — 20.07.2026 20:29
-
20.07.2026 20:29 1 articles · 12h ago
Rapid7 recovers an exposed 1,048-file phishing toolkit
Initial DisclosureRapid7 pulled down a delivery server left wide open and recovered 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. The artifacts point to an LLM-assisted workflow for producing and testing phishing delivery, and the exposed toolkit also held a 59-file test kit for CVE-2025-33053 WebDAV hijacks plus smaller sets for CVE-2026-21513 and CVE-2025-24054.
Show sources
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — thehackernews.com — 20.07.2026 20:29