One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware.

The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used to track victim activity.

The operation targeted Windows users with fake documents, identity-record downloads, error pages, and familiar business themes.

Victims could be pushed toward remote WebDAV shares, malicious shortcuts, or ClickFix-style instructions that persuade them to run commands themselves, a delivery pattern also seen in Windows File Explorer and WebDAV abuse campaigns.

Snippet of one of many subfolders containing testing files (Source - Rapid7)
Snippet of one of many subfolders containing testing files (Source – Rapid7)

Analysts at Rapid7 identified the infrastructure after an alert showed a user executing content retrieved through WebDAV with rundll32.exe.

Rapid7 said in a report shared with Cyber Security News (CSN) that the discovery revealed an active testing and delivery environment rather than a server hosting a single payload.

GenAI-Powered Malware Factory

The exposed directory contained 1,048 artifacts arranged like a development workspace.

It included 453 shortcut-based delivery launchers, 236 file-name spoofing tests, 146 URL and trusted-Windows-tool execution tests, 89 encrypted droppers, WebDAV scripts, ClickFix pages, and internal operator documentation.

The actor appeared to use generative AI to speed up repetitive work, including lure-writing, test documentation, and structured README files.

Phishing page impersonating Mexico’s CURP lookup service (Source - Rapid7)
Phishing page impersonating Mexico’s CURP lookup service (Source – Rapid7)

Researchers found detailed guidance for testing many Windows binaries, showing how a single technique could be adapted, checked, and refined much like a software team testing a new product.

One major focus was CVE-2025-33053, a Windows shortcut flaw previously associated with WebDAV working-directory abuse.

The technique can cause a legitimate Windows program to load a similarly named file from an attacker-controlled remote location, an approach discussed in coverage of Windows WebDAV zero-day exploitation.

Execution chain (Source - Rapid7)
Execution chain (Source – Rapid7)

The server also held decoy documents using double extensions, Unicode tricks, right-to-left override characters, misleading icons, and hidden command windows.

These details matter because the campaign depended less on exploiting a victim’s technical weakness and more on making harmful files look like everyday paperwork.

Campaign Reach and Defense

One observed campaign impersonated Mexico’s CURP national identity lookup service and sent victims to a fraudulent site.

After a visitor entered identity information and selected a download option, the site triggered a search-ms request that opened a remote WebDAV share instead of providing a legitimate PDF.

DlrtyGames execution chain (Source - Rapid7)
DlrtyGames execution chain (Source – Rapid7)

The main lure was accessed in a way consistent with attempted execution 2,384 times, while the server recorded 77,098 requests from 3,892 client IP addresses across 101 countries.

Mexico accounted for 82.5 percent of requests and nearly all observed launch activity, although a launch event does not by itself prove the malware ran successfully.

The delivered payloads included a fileless information stealer and a modular remote-access tool.

They were designed to collect browser credentials, cookies, wallet data, messaging sessions, screenshots, and keystrokes, while using process injection and other methods to make detection harder.

Similar social-engineering pressure is central to recent ClickFix campaign guidance, where fake verification steps lead users to run attacker-provided commands.

Simba service presentation (Source - Rapid7)
Simba service presentation (Source – Rapid7)

Organizations should treat unusual WebDAV activity as a priority signal, especially when it follows phishing messages or involves Windows utilities fetching remote content.

Security teams should audit command lines involving rundll32.exedavclnt.dll, and other trusted tools, restrict unnecessary outbound WebDAV access, and train staff not to copy commands from unexpected verification or document-access pages, as outlined in WebDAV rundll32 detection advice.

The case shows how generative AI can make malicious operations faster without necessarily creating entirely new malware.

The greater risk is operational scale: attackers can produce more believable lures, test more delivery paths, and quickly adjust campaigns when a method fails.

Indicators of Compromise (IoCs):-

Type Indicator Description
Phishing domain hxxps://gobf.mx CURP campaign phishing page
WebDAV domain onedrive.cv WebDAV delivery server
File ReportFinal.RLO.scr CURP campaign lure
SHA-256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7C2 ReportFinal.RLO.scr
IP address 77.110.127.205 CURP campaign C2 infrastructure
Ports 56001-56003, 57666, 57777, 57888 Associated C2 ports
Domain google.services.ug C2 alias/domain
Campaign tag 06x12x2026SantaEbash2 v4.4.3 Stealer configuration tag
Scheduled tasks brokerhostnetqueue32 Possible persistence artifacts
Staging paths TEMP-XXXXX.tmp-Binary.exeAppData\i686prod CURP campaign staging artifacts
C2 endpoint 23.94.252.228:57666 DlrtyGames campaign C2
JA3 fc54e0d16d9764783542f0146a98b300 TLS client fingerprint
File DlrtyGames.exe DlrtyGames dropper
SHA-256 e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268 DlrtyGames.exe
File discord-rpc.x64.dll DLL sideloading component
SHA-256 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df discord-rpc.x64.dll
File profiler16.dll Loader component
SHA-256 a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9 profiler16.dll
File loader-pool.db Image-carried encrypted module container
SHA-256 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b loader-pool.db
SHA-256 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923 .NET RAT payload
Staging path C:\APPDATA\HKCU\appbg\i686\component\v832rc DlrtyGames campaign staging artifact

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *