Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
IncidentOur summary
A server used by a malware operator was left unsecured, allowing researchers at Rapid7 to recover a full toolkit containing lure templates, test files, and documentation. The data reveals an AI-assisted approach to crafting phishing attacks that exploit CVE-2025-33053 (CVSS 8.8), a WebDAV vulnerability patched in June 2025. The campaign targeted Mexican users via a fake government ID lookup site, delivering infostealers through malicious .scr files disguised as PDFs. Researchers found evidence suggesting the attackers used open-source AI coding tools to automate parts of their workflow, including generating phishing content and testing multiple signed binaries for potential hijack opportunities.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.