Security Alert Uncovers GenAI Malware Factory with 1,000+ Attack Files
Key Takeaways A single security alert led to the discovery of a sophisticated WebDAV server, revealing a threat actor’s entire malware development and delivery pipeline. The server contained...
Key Takeaways
- A single security alert led to the discovery of a sophisticated WebDAV server, revealing a threat actor’s entire malware development and delivery pipeline.
- The server contained over 1,000 attack files, including phishing lures, droppers, and testing documentation, indicating a highly organized operation.
- The threat actor leverages generative AI for tasks like writing phishing content and documentation, accelerating malware creation and refinement.
- Attacks primarily target Windows users, employing social engineering and exploiting vulnerabilities like CVE-2025-33053, a Windows shortcut flaw.
- The campaign has a global reach, with significant activity observed in Mexico, delivering fileless information stealers and modular remote-access tools.
Unveiling a GenAI-Powered Malware Factory
A recent security alert has provided an unprecedented look into the inner workings of a threat actor’s malware development and delivery infrastructure. This singular incident exposed a WebDAV server, which functioned as a comprehensive malware factory, containing more than 1,000 malicious files and detailed operational insights.
Table Of Content
The exposed server housed a vast array of attack components, including phishing templates, shortcut files designed for malicious execution, various droppers, internal testing notes, and tools specifically crafted to monitor victim interactions. The findings paint a clear picture of a well-organized and actively managed threat operation.
Targeting and Delivery Mechanisms
The malicious campaigns primarily target Windows users, employing deceptive tactics such as fake documents, counterfeit identity record downloads, misleading error pages, and business-themed lures. Attackers guide victims towards remote WebDAV shares, malicious shortcuts, or “ClickFix”-style instructions that trick users into executing commands themselves. This delivery method mirrors patterns observed in other campaigns leveraging Windows File Explorer and WebDAV vulnerabilities.
The discovery was initiated by analysts at Rapid7 after an alert indicated a user executing content retrieved via WebDAV using rundll32.exe. Rapid7’s subsequent investigation, detailed in a report, confirmed that the infrastructure was not merely hosting a single payload but served as an active environment for both testing and delivering a wide range of malware.
GenAI-Powered Malware Factory
The exposed directory was meticulously organized, resembling a professional development workspace, and contained 1,048 distinct artifacts. These included 453 shortcut-based launchers, 236 files used for spoofing filenames, 146 tests for URL and trusted Windows tool execution, 89 encrypted droppers, WebDAV scripts, ClickFix pages, and extensive internal operator documentation.
Researchers noted that the threat actor appears to be utilizing generative AI to streamline repetitive tasks. This includes automating the creation of phishing lures, drafting test documentation, and generating structured README files, significantly enhancing the efficiency of their malicious operations. The detailed guidance found for testing numerous Windows binaries suggests a structured approach, akin to a legitimate software development team rigorously testing a new product.
A significant focus of the actor’s development efforts was CVE-2025-33053, a Windows shortcut vulnerability previously linked to WebDAV working-directory abuse. This technique allows a legitimate Windows program to load a similarly named malicious file from an attacker-controlled remote location, a method explored in discussions surrounding Windows WebDAV zero-day exploitation.
The server also contained sophisticated decoy documents employing various evasion techniques, such as double file extensions, Unicode character tricks, right-to-left override characters, deceptive icons, and hidden command windows. These details highlight a strategy that relies heavily on social engineering, making harmful files appear as legitimate paperwork, rather than exploiting purely technical system weaknesses.
Campaign Reach and Defense
One particular campaign identified impersonated Mexico’s CURP national identity lookup service, directing victims to a fraudulent website. Upon entering identity information and attempting a download, the site initiated a search-ms request that opened a remote WebDAV share instead of providing the expected PDF document.
The primary lure in this campaign saw approximately 2,384 attempted executions. The server itself recorded 77,098 requests from 3,892 unique client IP addresses spanning 101 countries. Mexico accounted for 82.5% of these requests and nearly all observed launch activities, although a launch event does not definitively confirm successful malware execution.
The payloads delivered included a fileless information stealer and a modular remote-access tool. These tools are designed to harvest browser credentials, cookies, cryptocurrency wallet data, messaging session information, screenshots, and keystrokes. They also employ process injection and other anti-detection techniques to evade security measures. This use of social engineering to pressure users into executing attacker-provided commands is consistent with recent ClickFix campaign tactics.
The integration of generative AI into these operations enables attackers to achieve greater operational scale. It allows for the rapid production of more convincing lures, extensive testing of various delivery paths, and quick adaptation of campaigns when initial methods fail.
What You Should Do
- Organizations should prioritize and investigate any unusual WebDAV activity, particularly if it follows suspicious phishing attempts or involves Windows utilities fetching remote content.
- Security teams must conduct thorough audits of command lines that include
rundll32.exe,davclnt.dll, and other trusted tools, as these are frequently abused by attackers. - Restrict unnecessary outbound WebDAV access from your network to mitigate potential exfiltration and command-and-control communication.
- Implement robust employee training programs to educate staff on identifying and avoiding social engineering tactics, especially those involving unexpected verification steps or instructions to copy and execute commands from suspicious pages, as highlighted in WebDAV rundll32 detection advice.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.