One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
ID: 0c26c9d8-bed3-5370-9242-adc2f1a8ea79
STIX ID: report--0c26c9d8-bed3-5370-9242-adc2f1a8ea79
Feed Name: cybersecurityNews.com
Rapid7 discovered an exposed WebDAV server containing 1,048 artifacts that reveal a generative-AI-assisted malware development and delivery environment: phishing lures, shortcut-based launchers, encrypted droppers, testing notes, and operator docs. The operation targeted Windows users (notably in Mexico) using WebDAV shares, malicious shortcuts and ClickFix-style social engineering to push execution (observed rundll32.exe usage), delivered a fileless infostealer and modular RAT, and abused a Windows shortcut vulnerability (CVE-2025-33053); the report includes extensive IoCs (domains, IPs, file hashes, JA3, ports, staging paths) and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
