logo

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

ID: 5033aa96-8334-598f-9fc4-228697e7ba58

STIX ID: report--5033aa96-8334-598f-9fc4-228697e7ba58

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: [email protected] (The Hacker News)

...
...

Rapid7 discovered an exposed attacker repository and delivery panel containing 1,048 files — lure templates, tests, builder notes, and active delivery logs — tied to a phishing campaign targeting Mexican users that delivered an in-memory .NET infostealer (and a separate RAT via DLL sideloading). The operator exploited a WebDAV working-directory hijack (CVE-2025-33053) and probed dozens of signed binaries with .url shortcuts, leveraged LLM-assisted tooling to scale phishing development, and logged tens of thousands of delivery requests; Rapid7 published IOCs and recommends blocking the C2/hashes and monitoring for WebClient/davclnt.dll WebDAV activity and signed binaries loading children from UNC/WebDAV paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.