Executive Summary
In July 2026, cybersecurity firm Rapid7 discovered an exposed server containing a comprehensive AI-assisted phishing toolkit. The toolkit comprised 1,048 files, including lure templates, execution experiments, and builder notes. One active campaign targeted Windows users in Mexico, delivering an infostealer via a fake government ID-lookup site over WebDAV. The attack exploited CVE-2025-33053, a WebDAV working-directory hijack vulnerability, allowing attackers to execute malicious payloads without triggering security warnings. The operator utilized generative AI tools to rapidly develop and test phishing delivery methods, mirroring legitimate software development practices. This incident underscores the evolving threat landscape where cybercriminals leverage AI to enhance the sophistication and efficiency of their attacks. Organizations must adapt their defense strategies to counteract these advanced tactics, emphasizing the need for continuous monitoring, employee training, and the implementation of robust security measures to mitigate the risks posed by AI-driven cyber threats.
Why This Matters Now
The integration of AI into phishing campaigns signifies a significant escalation in cyber threats, enabling attackers to develop and deploy sophisticated attacks more efficiently. This trend necessitates immediate attention and adaptation of cybersecurity defenses to address the growing capabilities of AI-assisted cybercriminal activities.
Attack Path Analysis
The attacker initiated the campaign by exploiting a WebDAV vulnerability (CVE-2025-33053) to deliver an infostealer through a fake government ID-lookup site. Upon execution, the malware elevated privileges by leveraging legitimate signed Windows binaries to bypass security warnings. The malware then moved laterally within the network by exploiting other signed binaries and UAC-bypass candidates. It established command and control by connecting to attacker-controlled WebDAV servers, allowing remote execution of commands. The infostealer exfiltrated sensitive data, including cryptocurrency wallets and browser credentials, to the attacker's servers. The campaign's impact was significant, with over 77,000 requests from nearly 4,000 unique IPs across 101 countries, primarily targeting Mexican users.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a WebDAV vulnerability (CVE-2025-33053) to deliver an infostealer through a fake government ID-lookup site.
Related CVEs
CVE-2025-33053
CVSS 8.8A remote code execution vulnerability in Microsoft WebDAV allows attackers to execute arbitrary code over a network by manipulating file names or paths.
Affected Products:
Microsoft Windows 10 – Version 1507, Version 1607, Version 1809, Version 21H2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
User Execution
Phishing
Ingress Tool Transfer
Command and Scripting Interpreter
Modify Registry
OS Credential Dumping
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Fake government ID-lookup sites targeting Mexican users expose citizen data through WebDAV-delivered infostealers, compromising identity verification systems and citizen services.
Banking/Mortgage
AI-assisted phishing toolkits create sophisticated lures targeting financial credentials, with infostealers bypassing traditional security through encrypted traffic and lateral movement.
Computer Software/Engineering
WebDAV malware campaigns exploit software distribution channels, requiring zero trust segmentation and egress filtering to prevent infostealer deployment and data exfiltration.
Information Technology/IT
Exposed phishing toolkit reveals 1,048 attack files targeting IT infrastructure, demanding enhanced multicloud visibility and threat detection for anomalous automation patterns.
Sources
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaignhttps://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.htmlVerified
- Remote Code Execution Vulnerability in Microsoft WebDAVhttps://securityvulnerability.io/vulnerability/CVE-2025-33053Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and controlled access policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the WebDAV vulnerability may have been constrained by limiting exposure of vulnerable services to untrusted networks.
Control: Zero Trust Segmentation
Mitigation: The malware's ability to escalate privileges could have been limited by enforcing strict segmentation policies that restrict access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The malware's lateral movement within the network could have been restricted by enforcing east-west traffic controls.
Control: Multicloud Visibility & Control
Mitigation: The malware's ability to establish command and control channels may have been constrained by monitoring and controlling outbound connections.
Control: Egress Security & Policy Enforcement
Mitigation: The exfiltration of sensitive data could have been limited by enforcing strict egress policies.
The overall impact of the campaign could have been reduced by limiting the attacker's ability to propagate and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Public Citizen Services
- Government ID Verification
- Online Service Portals
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of personal identification information (PII) of Mexican citizens.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, preventing unauthorized access and data exfiltration.
- • Utilize Egress Security & Policy Enforcement to filter outbound traffic and block connections to known malicious domains.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems to mitigate vulnerabilities like CVE-2025-33053, reducing the risk of exploitation.



