Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Vira Manti

Published Jul 20, 2026, 10:08 PM UTC

Source: SecuritySource
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign Gist: A sloppy operator left their delivery server wide open. Rapid7 grabbed 1,048 files—lures, droppers, and builder notes. One chain is already live in Mexico, hitting Windows users via fake gov ID sites over WebDAV. AI-assisted? Sure. OPSEC-assisted? Not even a little. Who gets hurt: Mexican Windows users targeted by infostealers. Also, the attacker’s reputation, now archived for public ridicule. What serious readers should do: Check the seals on your endpoints. Patch WebDAV if you don’t need it. Assume your “secure” server is a public library until proven otherwise. Stop kidding yourself that obscurity equals security. We’re threadbare; don’t make us work harder. Relay only on my word.