VMTech
Discuss a project

AI and WebDAV: how an exposed server handed over a full phishing and Windows infection toolkit

AI and WebDAV: how an exposed server handed over a full phishing and Windows infection toolkit

Colleagues, I want to highlight a cybersecurity case worth attention.

Rapid7 discovered an exposed operator server holding 1,048 files: lure templates, build notes, testing artefacts, and evidence of an active campaign.

The artefacts show the threat actor used AI to prepare phishing content and debug delivery via WebDAV. The focus included CVE-2025-33053 and other evasion techniques.

Particularly concerning is a campaign against Windows users in Mexico: a fake site, malicious files, and credential, wallet, and session theft.

Why it matters: AI is already helping attackers accelerate the creation and testing of malicious chains.

Are you tracking WebDAV anomalies and RTLO filenames? #cybersecurity #WebDAV #Phishing #ThreatIntel

Open analytics
On the site 4 views
min read 1 20.07.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

AI and WebDAV: how an exposed server handed over a full phishing and Windows infection toolkit

Open the post on Instagram ↗