Incident malware phishing
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
Executive summary
An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.…