CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2856

As cited

Copy frozen at (site build).

threat intel

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Rapid7 researchers accessed an unsecured server operated by malware distributors and retrieved over 1,000 files documenting an AI-assisted phishing toolkit. The cache included lure templates, execution tests, and droppers, with evidence of active campaigns targeting Windows users in Mexico through fake government websites delivering infostealers via WebDAV.

Why it matters: Organizations and security teams need visibility into emerging AI-augmented phishing infrastructure and delivery chains; this incident demonstrates the tooling adversaries are deploying at scale and the importance of monitoring for WebDAV-based malware delivery.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Researchers discovered an openly accessible server used by a malware operator to host its phishing toolkit. The exposed repository includes 1,048 files such as lure templates, filename‑spoofing tests, droppers, and notes for two campaign chains. One of those chains is currently delivering an infostealer to Windows users in Mexico through a fake government ID‑lookup site accessed via WebDAV.

Why it matters: Windows users in Mexico face active infostealer infection via WebDAV‑based phishing; defenders should block unsolicited WebDAV connections and scan for the identified lure templates.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Researchers discovered an openly accessible server used by a malware operator to host its phishing toolkit. The exposed repository includes 1,048 files such as lure templates, filename‑spoofing tests, droppers, and notes for two campaign chains. One of those chains is currently delivering an infostealer to Windows users in Mexico through a fake government ID‑lookup site accessed via WebDAV.

Why it matters: Windows users in Mexico face active infostealer infection via WebDAV‑based phishing; defenders should block unsolicited WebDAV connections and scan for the identified lure templates.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary