Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
ID: 5033aa96-8334-598f-9fc4-228697e7ba58
STIX ID: report--5033aa96-8334-598f-9fc4-228697e7ba58
Feed Name: The Hacker News
Rapid7 discovered an exposed attacker repository and delivery panel containing 1,048 files — lure templates, tests, builder notes, and active delivery logs — tied to a phishing campaign targeting Mexican users that delivered an in-memory .NET infostealer (and a separate RAT via DLL sideloading). The operator exploited a WebDAV working-directory hijack (CVE-2025-33053) and probed dozens of signed binaries with .url shortcuts, leveraged LLM-assisted tooling to scale phishing development, and logged tens of thousands of delivery requests; Rapid7 published IOCs and recommends blocking the C2/hashes and monitoring for WebClient/davclnt.dll WebDAV activity and signed binaries loading children from UNC/WebDAV paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
