Skip to content

AI-Powered Phishing Toolkit Exposed Through Unsecured Server

Key point: Attackers use open-source AI tools to industrialize the development of phishing and malware infrastructure, accelerating processes and testing variants against security vulnerabilities.

Rapid7 discovered an unprotected server where an attacker group had developed and tested phishing campaigns with support from Large Language Models. The forensic artifacts indicate systematic infrastructure development in the manner of a professional software team.

Security provider Rapid7 analyzed the development toolkit of an attacker group after discovering an unsecured distribution server. The server contained 1,048 files: templates for deception pages, test suites for filename manipulation, execution scripts, and execution logs. The directory structures and artifacts show that the operator used open-source AI programming tools such as Coderrr to accelerate the development, testing, and documentation of phishing infrastructure and malware. The administration interface of the distribution platform “Simba Service” was also unprotected on the system.

The central development objective was the reproduction and extension of the Windows vulnerability CVE-2025-33053. This method uses a URL shortcut to launch a signed Windows file while redirecting the working directory to a WebDAV share controlled by the attacker. This causes Windows to load malicious components from the remote resource. After the original attack pattern stopped working on Windows 11 Version 24H2, the group created a test package with 59 URL files to check alternative signed Windows utilities such as InstallUtil and RegAsm for vulnerability.

Rapid7 documented an active attack wave against users in Mexico in parallel. The attackers operated a fake government website for national identification numbers, through which victims were directed to a WebDAV share. An executable file disguised as a PDF was downloaded there, which unpacked an infostealer. This malware obtained credentials for cryptocurrency wallets, browser sessions, and messenger services. Between 20 and 26 June 2026, 77,098 requests from 3,892 unique IP addresses from 101 countries were registered, of which 82.5 percent originated from Mexico.


Source: www.it-daily.net · Published 26 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: