{"id":1885,"date":"2026-07-20T18:35:47","date_gmt":"2026-07-20T18:35:47","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1885"},"modified":"2026-07-20T18:35:47","modified_gmt":"2026-07-20T18:35:47","slug":"exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1885","title":{"rendered":"Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJtNDirNuc1FHpVkk7dexa4KTcD8h3fSmxpGMZQeRtlzNpIhC5hOXVEu-aPc5tsCIi9-csPtQVmdoW9FeyyBytXkPWfbwYZEGSJrIiqSEqUsdQwGOepqr23C4pz6jnGWI5ledB7UC19S0ORrc_jyP6Lajqu0X4FsTX6ooTVJvJffKOjRmg2ndJLDj17-E\/s1700-e365\/phishing-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.<\/p>\n<p>What makes it more than a payload dump: it caught the operation mid-build. Testing notes, failed experiments, documentation, and live delivery logs sat in one place, the kind of complete development trail defenders rarely see.<\/p>\n<p>Rapid7<a href=\"https:\/\/www.rapid7.com\/blog\/post\/tr-exposed-webdav-malware-delivery-lab-analysis\/\" target=\"_blank\"> reads<\/a> the artifacts, down to a hardcoded path pointing at an open-source AI coding tool, as an operator using generative AI to produce, test, and document phishing delivery at speed.<\/p>\n<p>The most developed test set focused on <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-33053\" target=\"_blank\">CVE-2025-33053<\/a> (CVSS 8.8, now in <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">CISA&#8217;s KEV catalog<\/a>), the WebDAV working-directory hijack <a href=\"https:\/\/research.checkpoint.com\/2025\/stealth-falcon-zero-day\/\" target=\"_blank\">Check Point documented<\/a> last year in its Stealth Falcon reporting.<\/p>\n<p>The operator appeared to be reproducing it. The technique abuses a <code>.url<\/code> shortcut to launch a legitimate signed Windows binary while pointing its working directory at an attacker-controlled WebDAV share. In the original attack, the shortcut launched <code>iediagcmd.exe<\/code>, an Internet Explorer diagnostics tool that starts helpers like <code>route.exe<\/code> by bare filename; with the working directory pointed at the remote share, Windows loads the attacker&#8217;s <code>route.exe<\/code> from WebDAV instead of the real one in <code>System32<\/code>.<\/p>\n<p>The operator&#8217;s own README claims this runs with no SmartScreen or Mark-of-the-Web warning, \u00abWITHOUT any security warnings. Zero alerts!\u00bb Microsoft patched the flaw in June 2025.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The notes mirror Check Point&#8217;s writeup closely enough that one recovered README preserved the exact <code>summerartcamp[.]net@ssl@443\\DavWWWRoot\\OSYxaOjr<\/code> example path from the original report. Then the operator scaled the testing.<\/p>\n<p>One \u00abcomprehensive test kit\u00bb expanded the single technique into 59 <code>.url<\/code> files aimed at other signed binaries: .NET tools like <code>InstallUtil<\/code> and <code>RegAsm<\/code>, LOLBAS entries, even UAC-bypass candidates, each with a written theory of why the hijack should work and a tiered testing order.<\/p>\n<p>The notes treat these as candidates to probe one by one, not confirmed hijacks, and the operator built the set for a concrete reason: the original trick breaks on Windows 11 24H2, where Internet Explorer, and so <code>iediagcmd.exe<\/code>, is gone. The directory also held smaller test sets for two other file-handling flaws, the MSHTML bypass <a href=\"https:\/\/thehackernews.com\/2026\/03\/apt28-tied-to-cve-2026-21513-mshtml-0.html\" target=\"_blank\"><code>CVE-2026-21513<\/code> and the NTLM-leak <code>CVE-2025-24054<\/code>, but the WebDAV hijack was the main event.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhP_OWIBOiOL1d0L5-N-tArdc_qOWROMFtnQYPoh5Gmx0avgzzUomMR5BCbBBQqvzpm8_pSKJQgglogEbHl-mT5auCRtVtUW0kkArfNL6R5FcMs0EouCCtOixKOzN34KHdEZYYQiLHAikZmcIAsUeTRlVOZrpHdR0MuZ-OGngguxc0DfhZxGpsAyfmE-vI\/s1700-e365\/server.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhP_OWIBOiOL1d0L5-N-tArdc_qOWROMFtnQYPoh5Gmx0avgzzUomMR5BCbBBQqvzpm8_pSKJQgglogEbHl-mT5auCRtVtUW0kkArfNL6R5FcMs0EouCCtOixKOzN34KHdEZYYQiLHAikZmcIAsUeTRlVOZrpHdR0MuZ-OGngguxc0DfhZxGpsAyfmE-vI\/s1700-e365\/server.png\" alt=\"\" border=\"0\" data-original-height=\"608\" data-original-width=\"828\"\/><\/a><\/div>\n<p>The tell is in the paperwork. Rapid7 says the READMEs, lure-generation guides, matrix-style test write-ups, and a <code>_MAPPING.csv<\/code> tying each test file to its target binary carry the templated formatting, verbosity, and emoji-heavy structure it associates with LLM output.<\/p>\n<p>It reads the phishing site&#8217;s emoji-laden JavaScript the same way. The Russian comments and folder names, one called <code>testik<\/code> (a diminutive of \u00abtest\u00bb), place the operator in a Russian-speaking context but don&#8217;t identify them. Rapid7 attributes the operation to an LLM-assisted workflow, likely built with help from <a href=\"https:\/\/github.com\/Akash-nath29\/Coderrr\" target=\"_blank\">Coderrr<\/a>, which it renders \u00abCodeRRR.\u00bb<\/p>\n<p>The Hacker News confirmed the repository is public as of July 20, 2026: a general-purpose, open-source AI coding agent inspired by Claude Code, GitHub Copilot CLI, and Cursor, not attacker-specific tooling. Rapid7&#8217;s summary is blunt: \u00abthe attacker used LLMs to operate more like a modern software product team.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgef79v0s08aCYFh7_U_STctp_i9sdGf7NXVueaukEk_EKQ4xEhBaWn4j4eZxjg9f33Ykh0gMhr2oA3dLGCeHDR5WXUeAeKBPD4NjsRUziXdeZO4SAmddgPeE4F9Ay5nBghm7v8IzQ7YFaV_utXt9uqKEx6HbkhiBomLmEX5YPt6i35ELl4cf25UUJyOcA\/s1700-e365\/simba.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgef79v0s08aCYFh7_U_STctp_i9sdGf7NXVueaukEk_EKQ4xEhBaWn4j4eZxjg9f33Ykh0gMhr2oA3dLGCeHDR5WXUeAeKBPD4NjsRUziXdeZO4SAmddgPeE4F9Ay5nBghm7v8IzQ7YFaV_utXt9uqKEx6HbkhiBomLmEX5YPt6i35ELl4cf25UUJyOcA\/s1700-e365\/simba.png\" alt=\"\" border=\"0\" data-original-height=\"580\" data-original-width=\"828\"\/><\/a><\/div>\n<p>The operator even left the delivery panel, an admin tool called Simba Service, sitting on the same server with its default port and credentials unchanged.<\/p>\n<h2>An active campaign targeting Mexican users<\/h2>\n<p>The MDR alert traced back to <code>gobf[.]mx<\/code>, a typosquat of the government&#8217;s CURP national-ID lookup, which served victims a fake record-retrieval page whose download button fired a <code>search-ms:<\/code> query. That opened the operator&#8217;s WebDAV share as a Windows Explorer search filtered to <code>.scr<\/code> files.<\/p>\n<p>The most-delivered lure looked like a CURP PDF report but was a <code>.scr<\/code> executable, its filename flipped with a right-to-left override to read as a PDF. It was an Inno Setup installer that unpacked a loader and ran a .NET infostealer entirely in memory, hollowed into a signed Qihoo 360 process.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-2\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHcvlLVmAqlffm6kG54_0cGVf8WfcgzqT9B0fBSizSSeIjh8tBepXnrf6BMqKiG344WgqNejcRtEFKT1PmOzQNQBhdmu2iz9Po10z0SSDlFuZ37iip2uYibJDoxTEkbUI7Bx8NJM2Io_z_nl5p4YA-ZhqFLfi0GW1axyu-lQx-iytCn9RGSJ2iqCwdyv8m\/s1600\/sy-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The stealer grabbed cryptocurrency wallets, browser credentials, session cookies, and Telegram sessions. A second campaign directory, <code>DlrtyGames<\/code>, took a different route, sideloading a trojanized DLL through a signed Ubisoft binary to drop a modular .NET RAT.<\/p>\n<p>Over roughly 5.5 days (June 20 to 26, 2026 UTC), the delivery panel logged 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico alone driving 82.5% of traffic and 96.9% of launch activity. A single CURP lure accounted for 2,384 of the 2,441 launch events, about 97.7%.<\/p>\n<p>That figure measures delivery reach, not infections: Rapid7 counts a \u00ablaunch event\u00bb when the panel sees a client request or opens an executable from the share, not a confirmed run on an endpoint, and the traffic from the US and Germany looked more like scanning than victims. The activity also clustered in Mexican working hours, consistent with real users rather than automated scanners.<\/p>\n<p>For defenders, the June 2025 patch closed the original <code>iediagcmd.exe<\/code> path, but the 59-file kit shows the operator hunting other signed binaries that behave the same way. Rapid7 has published indicators for both campaigns, including C2 addresses and file hashes, on its <a href=\"https:\/\/github.com\/rapid7\/Rapid7-Labs\/tree\/main\/IOCs\/Simba%20Panel\" target=\"_blank\">GitHub<\/a>; block those first.<\/p>\n<p>For what the IOCs miss, watch the behavior the alert first caught: the WebClient service starting and <code>davclnt.dll<\/code> reaching a remote host, a signed binary spawning a child whose image path sits on a WebDAV or UNC share, and filenames using RTLO (<code>U+202E<\/code>), double extensions, or padding before <code>.exe<\/code> or <code>.scr<\/code>.<\/p>\n<p>The Hacker News has reached out to Rapid7 for clarification on the final payload identification and the current status of the exposed infrastructure, and will update this story with any response.<\/p>\n<p>The delivery burst was short-lived, cooling after June 24. What lasts is the method: an operator wired commodity AI coding tools, never built for the job, into a repeatable pipeline for producing and testing phishing delivery, ready to point at the next target.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1886,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[170,6,137,42,390,475,518,958,2635],"class_list":["post-1885","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aiassisted","tag-campaign","tag-exposed","tag-malware","tag-phishing","tag-reveals","tag-server","tag-toolkit","tag-webdav"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1885"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1885\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1886"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}