Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Sophisticated AI-Assisted Phishing Toolkit Uncovered by Rapid7, Revealing Evolving Cybercrime Tactics

Cahyo Dewo, July 20, 2026

A groundbreaking discovery by cybersecurity firm Rapid7 has shed light on an advanced malware operation, revealing an attacker’s intricate toolkit left exposed on a delivery server. This unprecedented find, comprising 1,048 files, offers a rare, real-time glimpse into the development lifecycle of a sophisticated phishing campaign, strongly suggesting the use of generative artificial intelligence (AI) to accelerate and refine attack methodologies. The exposed infrastructure detailed a live campaign targeting Windows users in Mexico, deploying an infostealer via a deceptive government ID-lookup site leveraging WebDAV.

An Unprecedented Glimpse into Cybercrime Development

The trove of data Rapid7 secured was far more than a mere payload dump; it captured an operation mid-build, providing an unparalleled look at the attacker’s process. The exposed server contained a comprehensive collection of lure templates, meticulous filename-spoofing tests, detailed execution experiments, various droppers, internal builder notes, and records of two distinct campaign chains. Such a complete development trail, including failed experiments and live delivery logs, is a rarity for cybersecurity defenders, offering invaluable insights into modern threat actor tactics.

Rapid7’s analysis of these artifacts, which included a hardcoded path referencing an open-source AI coding tool, led to the conclusion that the operator was actively using generative AI to produce, test, and document their phishing delivery mechanisms at an accelerated pace. This finding underscores a significant shift in the cybercrime landscape, where AI tools are no longer just conceptual threats but active components in sophisticated attack workflows.

Generative AI: The New Frontier for Cyber Attackers

The most striking aspect of this discovery is the prominent role attributed to generative AI. Rapid7’s forensic examination of the operator’s documentation—including READMEs, lure-generation guides, matrix-style test write-ups, and a _MAPPING.csv file linking test files to target binaries—revealed templated formatting, verbose explanations, and an emoji-heavy structure. These characteristics are increasingly associated with output generated by Large Language Models (LLMs). The phishing site’s JavaScript, similarly adorned with emojis, further supported this assessment.

While the presence of Russian comments and folder names, such as testik (a diminutive for "test"), indicates a Russian-speaking origin for the operator, Rapid7 attributes the overall efficiency and scale of the operation to an LLM-assisted workflow, likely powered by a tool named Coderrr. The Hacker News confirmed on July 20, 2026, that Coderrr is a publicly available, general-purpose, open-source AI coding agent. It draws inspiration from established AI development tools like Claude Code, GitHub Copilot CLI, and Cursor, signifying its accessibility to a wide range of users, including malicious actors.

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Rapid7’s summary of this finding was stark: "the attacker used LLMs to operate more like a modern software product team." This statement highlights a worrying trend where AI is democratizing and professionalizing cybercrime, enabling individuals or smaller groups to achieve the operational sophistication traditionally associated with well-funded state-sponsored or organized criminal enterprises. The ability of AI to rapidly generate code, test variations, and even document processes significantly reduces the skill barrier and accelerates the development cycle for malicious tools.

Exploiting Critical Vulnerabilities: The WebDAV Hijack

A significant portion of the attacker’s efforts was dedicated to exploiting a specific, high-severity vulnerability: CVE-2025-33053 (CVSS 8.8). This flaw, now listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, pertains to a Web Distributed Authoring and Versioning (WebDAV) working-directory hijack. Check Point originally documented this vulnerability last year in its "Stealth Falcon" reporting, making it a well-known exploit in the cybersecurity community.

The operator appeared intent on reproducing and expanding upon this technique. The core mechanism of CVE-2025-33053 abuses a .url shortcut file to launch a legitimate, digitally signed Windows binary. Crucially, it manipulates the binary’s working directory, redirecting it to an attacker-controlled WebDAV share. In Check Point’s original discovery, the shortcut launched iediagcmd.exe, an Internet Explorer diagnostics tool. This tool, when executed, would then attempt to start helper utilities like route.exe using only their bare filenames. By pointing the working directory to the remote malicious WebDAV share, Windows would load the attacker’s fraudulent route.exe from the share instead of the genuine one located in System32, effectively executing malicious code under the guise of a legitimate process.

The operator’s internal README explicitly boasted about the efficacy of this technique, claiming it bypassed standard security measures: "WITHOUT any security warnings. Zero alerts!" This refers to the ability to circumvent Microsoft’s SmartScreen and Mark-of-the-Web (MotW) warnings, which are designed to alert users about potentially unsafe files downloaded from the internet. Microsoft subsequently patched this critical flaw in June 2025, but the attacker’s toolkit demonstrated a proactive effort to find alternative bypasses.

Scaling the Attack Surface: A Comprehensive Test Kit

The attacker’s notes mirrored Check Point’s write-up so closely that one recovered README even preserved the exact example path from the original report: summerartcamp[.]net@ssl@443DavWWWRootOSYxaOjr. This indicates direct replication or heavy reliance on publicly available exploit details. However, the operator didn’t stop at mere reproduction; they significantly scaled their testing efforts.

The exposed toolkit included a "comprehensive test kit" that expanded the single WebDAV hijack technique into 59 distinct .url files. Each of these files was aimed at other legitimate signed Windows binaries, exploring a broader attack surface. These targets included .NET tools like InstallUtil and RegAsm, various Living Off The Land Binaries and Scripts (LOLBAS) entries, and even candidates for User Account Control (UAC) bypasses. For each test, the operator had documented a theoretical explanation of why the hijack should work and a tiered testing order, indicating a methodical approach to exploit discovery.

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

These notes explicitly treated these as candidates to be probed, not confirmed hijacks, highlighting the operator’s iterative development process. The primary motivation for this extensive search was practical: the original iediagcmd.exe trick became obsolete with Windows 11 24H2, which removed Internet Explorer and, consequently, its diagnostic tool. This forced the attacker to seek new avenues for exploiting the WebDAV working-directory hijack.

Beyond the main WebDAV focus, the directory also contained smaller test sets for two other file-handling flaws: the MSHTML bypass CVE-2026-21513 and the NTLM-leak CVE-2025-24054. While these were secondary to the WebDAV exploit, their inclusion demonstrates the operator’s comprehensive approach to identifying and leveraging various vulnerabilities. MSHTML bypasses can allow for arbitrary code execution through crafted web content, while NTLM leaks can expose user credentials, both highly valuable to attackers.

Compounding the attacker’s carelessness, the operator even left their delivery panel, an administrative tool dubbed "Simba Service," exposed on the same server, complete with its default port and unchanged credentials. This administrative oversight provided Rapid7 with an unparalleled view into the operational aspects of the campaign.

An Active Campaign Targeting Mexican Users

The discovery traced back to an active campaign, with a significant focus on Mexican users. The primary vector was gobf[.]mx, a sophisticated typosquatting domain designed to mimic the legitimate Mexican government’s CURP national-ID lookup service. Victims visiting this fraudulent site were presented with a fake record-retrieval page. Upon clicking a seemingly innocuous download button, a search-ms: query was triggered. This query opened the operator’s malicious WebDAV share directly within Windows Explorer, filtered to display .scr (screensaver) files.

The most frequently delivered lure was disguised as a CURP PDF report. However, it was, in reality, a .scr executable. The attacker employed a right-to-left override (RTLO) Unicode character in the filename to manipulate its display, making an executable appear as a PDF file to unsuspecting users. This .scr file was an Inno Setup installer. Once executed, it unpacked a loader that then ran a .NET infostealer entirely in memory, hollowed into a legitimate, signed Qihoo 360 process to evade detection.

This sophisticated infostealer was designed to exfiltrate a wide array of sensitive data, including cryptocurrency wallets, browser credentials, stored session cookies, and active Telegram sessions—all highly valuable assets for cybercriminals.

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A second, distinct campaign directory found on the server, named DlrtyGames, revealed a different attack chain. This campaign involved sideloading a trojanized DLL through a signed Ubisoft binary, ultimately dropping a modular .NET Remote Access Trojan (RAT). This modular RAT would grant the attacker extensive control over compromised systems, allowing for further data exfiltration, surveillance, and potentially the deployment of additional malware.

Scale, Scope, and Geographic Distribution

Analysis of the delivery panel logs provided critical insights into the campaign’s reach and activity. Over approximately 5.5 days, from June 20 to June 26, 2026 UTC, the panel recorded an astonishing 77,098 requests originating from 3,892 unique IP addresses across 101 countries. The geographic distribution, however, showed a clear primary target: Mexico accounted for a dominant 82.5% of the overall traffic and an even higher 96.9% of the recorded launch activity. A single CURP lure was responsible for 2,384 of the total 2,441 launch events, representing about 97.7% of the total, underscoring its effectiveness in the Mexican context.

It is important to note that these figures represent "delivery reach" rather than confirmed infections. Rapid7 defines a "launch event" as a client request to the panel or the opening of an executable from the share, not necessarily a successful compromise of an endpoint. The analysis also indicated that traffic from countries like the United States and Germany appeared to be more indicative of scanning activities rather than actual victim engagement. The clustering of activity during Mexican working hours further supports the conclusion that the campaign was effectively reaching and engaging real users in the target region, distinguishing genuine victim interaction from automated reconnaissance.

The delivery burst, while intense, was relatively short-lived, with activity cooling down after June 24, 2026. However, the methods employed and the insights gained into the attacker’s AI-assisted workflow have long-lasting implications for cybersecurity.

Defender’s Response and Mitigation Strategies

In response to this significant discovery, Rapid7 has proactively published indicators of compromise (IOCs) for both campaigns. These IOCs, available on Rapid7’s GitHub repository, include critical command-and-control (C2) addresses and file hashes, enabling organizations to block known malicious infrastructure and artifacts immediately. Prioritizing the blocking of these IOCs is a crucial first step for defenders.

Beyond specific IOCs, Rapid7 also emphasized the importance of behavioral monitoring, which was instrumental in the initial detection of this threat. Defenders should vigilantly watch for:

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
  • The WebClient service initiating and davclnt.dll attempting to reach a remote host, indicating potential WebDAV activity.
  • A signed legitimate binary spawning a child process whose image path resides on a WebDAV or Universal Naming Convention (UNC) share, a tell-tale sign of the working-directory hijack technique.
  • Filenames employing Right-to-Left Override (RTLO) Unicode characters (U+202E), double extensions, or excessive padding before .exe or .scr extensions, all common obfuscation tactics used by attackers.

Regular patching remains a fundamental defense. The June 2025 patch, which closed the original iediagcmd.exe path for CVE-2025-33053, demonstrates the critical role of timely updates. However, the attacker’s 59-file test kit clearly illustrates their intent to continually hunt for other signed binaries exhibiting similar exploitable behaviors, highlighting the ongoing cat-and-mouse game between attackers and defenders.

The Hacker News has reached out to Rapid7 for further clarification regarding the final payload identification and the current status of the exposed infrastructure and will provide updates as information becomes available.

The Evolving Landscape of Cybercrime: AI’s New Frontier

This incident serves as a stark warning about the evolving nature of cybercrime. The discovery of an operator seamlessly integrating commodity AI coding tools—tools never explicitly designed for malicious purposes—into a repeatable pipeline for producing and testing phishing delivery is a game-changer. It signifies a future where sophisticated, customized attacks can be generated with greater speed, efficiency, and scale, even by less experienced actors.

The ability of generative AI to assist in creating highly convincing phishing lures, generating code for exploit variations, and even documenting the development process, empowers attackers to operate with unprecedented agility. This shift demands a corresponding evolution in defensive strategies, moving beyond signature-based detection to more advanced behavioral analysis, proactive threat hunting, and the development of AI-powered defensive tools capable of countering AI-powered attacks. The cyber security community must adapt quickly to this new frontier, as the weaponization of AI in cyber warfare is no longer a distant threat but a present reality, ready to be pointed at the next vulnerable target.

Cybersecurity & Digital Privacy assistedCybercrimeevolvingHackingphishingPrivacyrapidrevealingSecuritysophisticatedtacticstoolkituncovered

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes