Stealth Falcon APT Exploits Microsoft RCE Zero-Day in Mideast
ID: 828631dd-7e6f-5720-87e0-0404451b06c4
STIX ID: report--828631dd-7e6f-5720-87e0-0404451b06c4
Feed Name: Dark Reading
Threat Score
Stealth Falcon (aka FruityArmor) is exploiting a Microsoft WEBDAV zero-day (CVE-2025-33053, CVSS 8.8) via spear-phishing links to achieve one-click RCE and deploy the Horus Agent backdoor that integrates with Mythic C2; Microsoft addressed this and 65 other vulnerabilities in its June 2025 patch release and organizations—particularly defense and government entities in the Middle East and Africa—are urged to prioritize updates and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
