Incident phishing ai-ml
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
CVE Tools coverage
A server used by a malware operator was left unsecured, allowing researchers at Rapid7 to recover a full toolkit containing lure templates, test files, and documentation. The data reveals an AI-assisted approach to crafting phishing attacks that exploit CVE-2025-33053 (CVSS 8.8), a WebDAV vulnerability patched in June 2025. The campaign targeted Mexican users via a fake government ID lookup site, delivering infostealers through malicious .scr files disguised as PDFs. Researchers found evidence suggesting the attackers used open-source AI coding tools to automate parts of their workflow, including generating phishing content and testing multiple signed binaries for potential hijack opportunities.