logo

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

ID: 0c26c9d8-bed3-5370-9242-adc2f1a8ea79

STIX ID: report--0c26c9d8-bed3-5370-9242-adc2f1a8ea79

Feed Name: cybersecurityNews.com

Threat Score
76/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Tushar Subhra Dutta

...
...

Rapid7 discovered an exposed WebDAV server containing 1,048 artifacts that reveal a generative-AI-assisted malware development and delivery environment: phishing lures, shortcut-based launchers, encrypted droppers, testing notes, and operator docs. The operation targeted Windows users (notably in Mexico) using WebDAV shares, malicious shortcuts and ClickFix-style social engineering to push execution (observed rundll32.exe usage), delivered a fileless infostealer and modular RAT, and abused a Windows shortcut vulnerability (CVE-2025-33053); the report includes extensive IoCs (domains, IPs, file hashes, JA3, ports, staging paths) and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.