Exposed WebDAV delivery server leaked an AI-assisted phishing toolkit
Source headline: Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Intelligence Summary
A misconfigured malware delivery server was left accessible, letting Rapid7 download a full phishing toolkit. The archive includes lure templates, filename spoofing tests, execution experiments, and dropper/build components. One campaign was reportedly already targeting Windows users in Mexico. Victims were lured via a fake government ID-lookup site and served an infostealer through WebDAV. The exposure highlights how quickly phishing infrastructure can be reused or adapted if it remains publicly reachable.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.