logo

Stealth Falcon APT Exploits Microsoft RCE Zero-Day in Mideast

ID: 828631dd-7e6f-5720-87e0-0404451b06c4

STIX ID: report--828631dd-7e6f-5720-87e0-0404451b06c4

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-06-10

Date Updated: 2026-04-21

Author: Tara Seals

...
...

Stealth Falcon (aka FruityArmor) is exploiting a Microsoft WEBDAV zero-day (CVE-2025-33053, CVSS 8.8) via spear-phishing links to achieve one-click RCE and deploy the Horus Agent backdoor that integrates with Mythic C2; Microsoft addressed this and 65 other vulnerabilities in its June 2025 patch release and organizations—particularly defense and government entities in the Middle East and Africa—are urged to prioritize updates and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.