🟡 Medium | Source: The Hacker News
A threat actor accidentally exposed their malware staging server, allowing Rapid7 researchers to download over 1,000 files revealing a sophisticated, AI-assisted phishing toolkit. The toolkit includes lure templates, droppers, and two active campaign chains — one already targeting Windows users in Mexico via a fake government website delivering an infostealer over WebDAV. The exposure provides rare visibility into a modern, AI-augmented attack workflow from initial lure creation through to payload delivery.
Security Architect’s Take: Review egress controls and WebDAV access policies on your cloud workloads — WebDAV is rarely needed and should be blocked at the network layer or via cloud-native security groups. Additionally, assess whether your email and web proxy controls would catch spoofed-filename lures, and consider deploying cloud-based sandbox detonation for files fetched over legacy protocols.
Original advisory: Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign