News · curated 20 Jul 2026

Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation

Coverage timeline

discovered rapid7.com primary 20 Jul 2026thehackernews.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

The exposed toolkit is concrete evidence of attackers leveraging generative AI coding tools to accelerate malware and phishing development, a trend defenders must factor into the pace and scale of emerging campaigns.

Rapid7 recovered a 1,048-file malware delivery toolkit from an operator's exposed server, including lure templates, droppers, testing notes and live logs for a WebDAV-based infostealer campaign targeting Windows users in Mexico via a fake government ID-lookup site. Artifacts, including a hardcoded path pointing at an open-source AI coding tool, indicate the operator used generative AI to produce, test, and document the phishing delivery chain at speed.