AI-Assisted WebDAV Phishing Toolkit Campaign
First seen Jul 21, 2026 · Updated Jul 21, 2026
Rapid7 researchers discovered an exposed, misconfigured delivery server belonging to a malware operator, revealing over 1,000 files including phishing lure templates, filename-spoofing tests, droppers, and builder notes. The toolkit was actively used in a campaign targeting Windows users in Mexico via a fake government ID-lookup site, delivering an infostealer through WebDAV. The exposure suggests use of AI-generated content in crafting lures, lowering the barrier for producing convincing localized phishing pages.
Technical Analysis
The campaign leverages WebDAV as a delivery mechanism, likely abusing Windows' native WebDAV client support to serve malicious files disguised as legitimate government documents, bypassing some traditional download-based detection. The exposed server contained filename-spoofing experiments and execution tests, indicating active tradecraft development around evading file-type detection and social engineering victims into executing droppers. Builder notes and lure templates suggest a semi-automated or AI-assisted content generation pipeline for producing convincing phishing pages at scale, targeting a specific regional population (Mexico) with government-themed lures. The final payload is an infostealer, which is designed to harvest credentials, session tokens, and stored secrets from infected Windows hosts. If deployed against endpoints used by developers or operators managing AI agent infrastructure, this infostealer could exfiltrate API keys, cloud credentials, or LLM service tokens stored locally, enabling downstream compromise of agent pipelines and connected tool integrations.
Affected Systems
Windows endpoints supporting WebDAV client connections; users interacting with spoofed government ID-lookup phishing sites in Mexico
Indicators of Compromise
- Fake government ID-lookup phishing site (domain not disclosed in source)
- WebDAV-based delivery server (IP not disclosed in source)
- Infostealer dropper files (hashes not disclosed in source)
Remediation Steps
- 1
Disable unnecessary WebDAV client functionality
Restrict or disable the WebClient service on Windows endpoints where not business-required to reduce this delivery vector.
- 2
Enhance phishing and DNS filtering
Block known malicious domains and monitor for lookalike government-themed phishing sites, particularly those targeting Mexican users.
- 3
Deploy endpoint detection for infostealers
Use EDR solutions capable of detecting credential-harvesting malware behavior, including unusual access to browser credential stores and stored secrets.
- 4
Rotate and vault credentials/API keys
For any endpoint suspected of compromise, immediately rotate stored credentials, API keys, and tokens, especially those used by automation, scripts, or AI agent tooling.
- 5
User awareness training
Educate users on verifying government service URLs and avoiding execution of unsolicited downloaded files, especially via WebDAV links.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.