Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server open, and Rapid7 pulled down the toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexic…
Intelligence analysis by Llama

A malware operator used an AI-assisted phishing toolkit to deliver an infostealer to Windows users in Mexico. The toolkit was left exposed on a server, revealing a complete development trail, including testing notes, failed experiments, and live delivery logs. The operator appeared to be using generative AI to produce, test, and document phishing delivery at speed.
Imagine a team of hackers using a super-powerful computer to create fake websites that look like real government sites. They use this computer to make the fake sites look real, test them to make sure they work, and then use them to steal people's information. This is what happened with a group of hackers who left their computer open and were caught by a company called Rapid7.
Analysis
A $60B Vote of Confidence
The malware operator's decision to leave the delivery server open and the toolkit exposed is a significant development in the world of cybercrime. It reveals the level of sophistication and organization that some attackers have achieved, and the use of AI-assisted phishing toolkits is a game-changer. The toolkit, which consisted of 1,048 files, included lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One of the campaigns was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.
Why Cursor?
Rapid7, the company that discovered the toolkit, attributes the operation to an LLM-assisted workflow, likely built with help from Coderrr, which it renders 'CodeRRR.' The Hacker News confirmed that the repository is public as of July 20, 2026, a general-purpose, open-source AI coding agent inspired by Claude Code, GitHub Copilot CLI, and Cursor, not attacker-specific tooling. Rapid7's summary is blunt: 'the attacker used LLMs to operate more like a modern software product team.'
The Road Ahead
The discovery of this AI-assisted phishing toolkit highlights the need for defenders to be aware of this new threat vector and to take steps to protect themselves. The toolkit's use of generative AI to produce, test, and document phishing delivery at speed is a significant development, and it is likely that we will see more of this in the future. Defenders need to be prepared to face this new threat and to take steps to protect themselves.
Key points
- A malware operator left its delivery server open, and Rapid7 pulled down the toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains.
- One campaign was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.
- The operator appeared to be using generative AI to produce, test, and document phishing delivery at speed.
- The toolkit's use of generative AI to produce, test, and document phishing delivery at speed is a significant development.
- Defenders need to be aware of this new threat vector and to take steps to protect themselves.
If this development plays out positively, it could lead to a greater awareness of the use of AI-assisted phishing toolkits and a greater effort to protect against them. This could lead to the development of new technologies and strategies to combat this threat, and it could ultimately lead to a safer online environment for everyone.
On the other hand, if this development plays out negatively, it could lead to a greater use of AI-assisted phishing toolkits and a greater number of successful attacks. This could lead to a loss of trust in online systems and a greater sense of vulnerability among users. It could also lead to a greater number of people being affected by these types of attacks, and it could ultimately lead to a less secure online environment.



