Between August and October 2025, a sophisticated phishing has emerged targeting Spanish-speaking users, via deceptive emails pretending to be official communications from the Colombian Attorney General's. The new phishing campaign, with its supposed court documents, aims to infect victims with the PureHVNC RAT malware.

The campaign uses a carefully designed strategy social engineering, luring victims with notifications of alleged lawsuits filed through labor courts.
This marks a significant shift in attack tactics, as threat actors are expanding the deployment of PureHVNC into areas previously unaffected by this malware.
See also: Gunra ransomware attacks Windows and Linux
How does the attack work?
The attack chain begins when recipients encounter an email containing an SVG attachment , which leads them through Google Drive . There, clicking on the document triggers an automatic download of a password-protected ZIP file . Inside this file is an executable file disguised as a court document with the name “02 BOLETA FISCAL.exe”. In reality, it is a legitimate javaw.exe file that has been reused for malicious DLL side-loading .
This initial stage deploys Hijackloader , an increasingly prevalent loader that was previously observed delivering RemcosRAT to CrowdStrike customers. IBM X-Force analysts identified this campaign as particularly noteworthy, as it represents the first observed instance of PureHVNC being delivered to Spanish-speaking users through such coordinated efforts .

PureHVNC malware: Features
The malware, which is typically sold on dark web forums and Telegram channels, exhibits advanced detection evasion capabilities that set it apart from typical remote access trojans .
See also: GhostCall & GhostHire: BlueNoroff's new campaigns
The malware operates through a sophisticated infection process multi-stagedesigned to evade detection. The attack exploits DLL side-loading, where the malicious JLI.dll hijacks Windows library loading processes to inject the second-stage payload, MSTH7EN.dll, directly into memory (using the LoadLibraryW() API function).
This shellcode is eventually loaded into vssapi.dll via memory manipulation techniques that include VirtualProtect() calls that modify the .text section to PAGE_EXECUTE_READWRITE permissions.
The third-stage payload contains encrypted configuration, including process name hashes that cause execution delays when security software is detected. When activated, the malware queries running processes and uses NtDelayExecution() API calls to halt execution, demonstrating awareness of its operational environment.
See also: GhostGrab: New Android malware steals banking credentials

The full infection chain eventually establishes communication with the command server sofiavergara[.]duckdns[.]org, giving attackers full remote access to compromised systems. This campaign highlights how judicial and legal issues continue to act as effective agents of social engineering, particularly against government and corporate officials in Latin America.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
