CVE Tools

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

The Hacker NewsBy The Hacker News

Incident

Our summary

A server used by a malware operator was left unsecured, allowing researchers at Rapid7 to recover a full toolkit containing lure templates, test files, and documentation. The data reveals an AI-assisted approach to crafting phishing attacks that exploit CVE-2025-33053 (CVSS 8.8), a WebDAV vulnerability patched in June 2025. The campaign targeted Mexican users via a fake government ID lookup site, delivering infostealers through malicious .scr files disguised as PDFs. Researchers found evidence suggesting the attackers used open-source AI coding tools to automate parts of their workflow, including generating phishing content and testing multiple signed binaries for potential hijack opportunities.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store