Skip to content

Exposed Server Reveals AI-Assisted Phishing Infrastructure Behind WebDAV Malware

The bottom line: A compromised malware delivery server exposed an AI-assisted phishing infrastructure actively deployed against end users, providing insights into operationalization processes and automation techniques.

Security researchers from Rapid7 have completely analyzed an unsecured malware delivery server and secured over 1,000 files, including phishing templates, payload builders, and two active campaign chains. One campaign is already targeting Windows users in Mexico with an infostealer.

Rapid7 researchers succeeded in documenting an unsecured delivery server of a malware operation. The secured infrastructure comprises 1,048 files: phishing lure templates, tests for filename spoofing, execution experiments, dropper code, as well as documentation and builder notes from the attacker.

Particularly relevant is the discovery of two active campaign chains. One of them is already targeting Windows users in Mexico, with the attackers distributing infostealer malware as a payload via a fake government website for government ID lookups (via WebDAV). This indicates an established operational pattern with a high success rate.

Access to the backend server enables CISOs and blue teams to understand the actual methods and automation techniques of the campaign — from lure creation to payload delivery. The integration of AI systems into the phishing workflow demonstrates the increasing professionalization of such attack campaigns and requires adaptation of detection and defense strategies.


Source: thehackernews.com · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: