Researchers detailed a phishing campaign that used an SVG attachment to launch JavaScript in the victim’s browser, drop an HTM file, and abuse the Windows search-ms handler with a WebDAV path to fetch additional stages. The infection chain pulled a VBScript, an obfuscated batch file, and Python-based payloads protected with Pyarmor 9, which analysts reverse engineered by unpacking the runtime’s AES-GCM and marshal customizations. The unpacked Python code decrypted RC4-protected shellcode, allocated executable memory, and launched a multi-stage sequence that included a laZzzy-generated injector targeting notepad.exe, more shellcode, and final .NET malware delivering DcRat, AsyncRAT, XWorm RAT, and PureHVNC.
The tradecraft closely matches activity previously attributed to DDGroup, a long-running cybercrime actor tied to phishing campaigns that weaponize search-ms and WebDAV to present attacker-hosted files as local search results. Prior reporting linked the group to commodity malware including XWorm, AsyncRAT, QuasarRAT, BitRat, Remcos, NetWire, Warzone RAT/AveMaria RAT, and ModiLoader/DBatLoader, along with dynamic DNS infrastructure, open-source tooling such as Freeze.rs and dufs, and repeated process injection into notepad.exe. Researchers said the actor’s infrastructure spans more than 110 dynamic DNS domains and 94 IP addresses since 2019, and that observed domains and URLs from the newer campaign were reported to URLhaus to speed blocking.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
The cyber.wtf article documents how the Pyarmor 9.0.7 Pro runtime was reverse engineered, including its AES-GCM handling and modified marshal logic, to statically unpack protected Python malware stages.
The Medium write-up attributes the broader search-ms and WebDAV malware delivery activity to a threat actor named DDGroup. It links the actor to commodity malware families including XWorm and AsyncRAT and to tooling such as dufs and a likely Freeze.rs-derived crypter.
Trellix published research describing how attackers abused the Windows search-ms URI handler against Windows users. The technique allowed redirection to attacker-controlled remote locations such as WebDAV shares.
In August 2023, the researcher observed an invoice-themed phishing email with a malicious PDF attachment that lured a victim into a search-ms redirect opening attacker-hosted content. Antivirus blocked execution in that specific case, preventing recovery of the final payload.
The researcher says DDGroup was among the early actors using OneNote files for malware delivery in 2023.
The article says DDGroup had been mentioned indirectly in public reporting since February 2022, though it had not yet been specifically named or described as a distinct actor.
The researcher states the threat cluster later named DDGroup can be tracked back to at least late 2019. The activity was linked across more than 110 dynamic DNS domains and 94 IP addresses.
The researchers reported the campaign's observed domains and download URLs to URLhaus to speed blocking of the malicious infrastructure.
Researchers analyzed a phishing campaign using an unpaid-invoice SVG lure that led through HTM, WebDAV, VBScript, batch, and Pyarmor-protected Python stages to shellcode, a laZzzy-style injector, and final .NET malware. The campaign delivered DcRat, AsyncRAT, XWorm RAT, and PureHVNC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.