News · curated 20 Jul 2026
Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation
First reported rapid7.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The exposed toolkit is concrete evidence of attackers leveraging generative AI coding tools to accelerate malware and phishing development, a trend defenders must factor into the pace and scale of emerging campaigns.
Rapid7 recovered a 1,048-file malware delivery toolkit from an operator's exposed server, including lure templates, droppers, testing notes and live logs for a WebDAV-based infostealer campaign targeting Windows users in Mexico via a fake government ID-lookup site. Artifacts, including a hardcoded path pointing at an open-source AI coding tool, indicate the operator used generative AI to produce, test, and document the phishing delivery chain at speed.