
Fake Mexico ID Site Pushed WebDAV Malware
Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live…
Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows “search-ms” link, where a disguised .scr file appeared to be a PDF.
Investigators found an exposed server acting as a fully operational malware delivery lab, containing over 1,000 artifacts used to test lures, filenames, and execution methods before real deployment. One active campaign impersonated a government ID lookup service through a typosquat domain, presenting a convincing page that asked victims to enter identity data and retrieve an official record. Instead of delivering a real PDF, the site triggered a search-ms link that opened a remote WebDAV folder as a Windows Explorer search view, filtered to show only .scr files disguised to look like documents.
The lab tested multiple ways to make executables look harmless, including Unicode spoofing, right-to-left override characters, double extensions, and padding tricks. A key lure file named to appear as a PDF was actually an RTLO-masked .scr executable that launched a multi-stage infection chain once opened. Because the delivery mechanism opened a folder view rather than a direct download, the process looked like normal file browsing rather than a suspicious executable launch.
The same lab tested other approaches beyond the fake PDF scenario:
Staff should be trained to treat lookalike domains as a major warning sign, particularly for portals resembling government or financial services. Reinforce that legitimate downloads do not open search windows or prompt command execution, and that any page asking someone to copy and paste a command to fix an error should be reported rather than followed. Recognizing file-masquerading tricks such as fake extensions and RTLO characters can help employees pause before opening unexpected files, even ones that appear to be routine documents.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It refers to an exposed server found with over 1,000 files used to test phishing lures, filenames, and execution tricks before deploying them in real campaigns.
A typosquat site impersonating a government ID lookup service used a search-ms link to open a remote WebDAV folder, where a file named to look like a PDF was actually an RTLO-masked .scr executable.
A search-ms URI opens a Windows Explorer search view instead of downloading a file directly, and attackers used it to display a remote WebDAV share as if it contained a normal document.
ClickFix pages mimic services like verification checks or update errors and instruct victims to copy and run a command, often to fetch or execute content from a remote WebDAV or UNC path.
Imagine you’re on a government site, downloading an official CURP record…and that “PDF” quietly installs malware instead. Investigators found a WebDAV “malware lab” with over a thousand test files. One live scam used a fake CURP site at www.gobf.mx, when you clicked download, it didn’t fetch a PDF. It fired a search-ms link that opened a remote WebDAV folder on your PC. Inside that folder, a file named 'ReportFinal.rcs.pdf' shows a PDF icon, but it’s actually a .scr executable using a right-to-left override trick. Same lab also pushed email shortcuts, .url files that quietly launch iediagcmd.exe to run malware from WebDAV with zero warnings. Your move: if a “download” opens a Windows search window or a network path instead of saving a file, especially from a lookalike site or a .url attachment, stop and report it to Security immediately.

Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live…

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…