Rapid7 uncovered an exposed malware delivery infrastructure that revealed 1,048 files, including live campaign artifacts, test kits, and documentation showing an operator using generative AI to build and test phishing delivery at speed. One active campaign targeted Mexican users through a fake CURP lookup site, delivering an infostealer via a WebDAV-based shortcut hijack tied to CVE-2025-33053. #Rapid7 #CVE-2025-33053 #gobfmx #CURP #SimbaService
Keypoints
- Rapid7 found 1,048 exposed files from a malware delivery server.
- The files showed live campaign logs, failed tests, builder notes, and lure templates.
- The operator appeared to use generative AI to create and document phishing workflows.
- One campaign abused a fake CURP site to deliver an infostealer to Mexican users.
- The toolkit included tests for CVE-2025-33053 and other Windows file-handling flaws.
Read More: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html