One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware.
The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used to track victim activity.
The operation targeted Windows users with fake documents, identity-record downloads, error pages, and familiar business themes.
Victims could be pushed toward remote WebDAV shares, malicious shortcuts, or ClickFix-style instructions that persuade them to run commands themselves, a delivery pattern also seen in Windows File Explorer and WebDAV abuse campaigns.
.webp)
Analysts at Rapid7 identified the infrastructure after an alert showed a user executing content retrieved through WebDAV with rundll32.exe.
Rapid7 said in a report shared with Cyber Security News (CSN) that the discovery revealed an active testing and delivery environment rather than a server hosting a single payload.
GenAI-Powered Malware Factory
The exposed directory contained 1,048 artifacts arranged like a development workspace.
It included 453 shortcut-based delivery launchers, 236 file-name spoofing tests, 146 URL and trusted-Windows-tool execution tests, 89 encrypted droppers, WebDAV scripts, ClickFix pages, and internal operator documentation.
The actor appeared to use generative AI to speed up repetitive work, including lure-writing, test documentation, and structured README files.
.webp)
Researchers found detailed guidance for testing many Windows binaries, showing how a single technique could be adapted, checked, and refined much like a software team testing a new product.
One major focus was CVE-2025-33053, a Windows shortcut flaw previously associated with WebDAV working-directory abuse.
The technique can cause a legitimate Windows program to load a similarly named file from an attacker-controlled remote location, an approach discussed in coverage of Windows WebDAV zero-day exploitation.
.webp)
The server also held decoy documents using double extensions, Unicode tricks, right-to-left override characters, misleading icons, and hidden command windows.
These details matter because the campaign depended less on exploiting a victim’s technical weakness and more on making harmful files look like everyday paperwork.
Campaign Reach and Defense
One observed campaign impersonated Mexico’s CURP national identity lookup service and sent victims to a fraudulent site.
After a visitor entered identity information and selected a download option, the site triggered a search-ms request that opened a remote WebDAV share instead of providing a legitimate PDF.
.webp)
The main lure was accessed in a way consistent with attempted execution 2,384 times, while the server recorded 77,098 requests from 3,892 client IP addresses across 101 countries.
Mexico accounted for 82.5 percent of requests and nearly all observed launch activity, although a launch event does not by itself prove the malware ran successfully.
The delivered payloads included a fileless information stealer and a modular remote-access tool.
They were designed to collect browser credentials, cookies, wallet data, messaging sessions, screenshots, and keystrokes, while using process injection and other methods to make detection harder.
Similar social-engineering pressure is central to recent ClickFix campaign guidance, where fake verification steps lead users to run attacker-provided commands.
.webp)
Organizations should treat unusual WebDAV activity as a priority signal, especially when it follows phishing messages or involves Windows utilities fetching remote content.
Security teams should audit command lines involving rundll32.exe, davclnt.dll, and other trusted tools, restrict unnecessary outbound WebDAV access, and train staff not to copy commands from unexpected verification or document-access pages, as outlined in WebDAV rundll32 detection advice.
The case shows how generative AI can make malicious operations faster without necessarily creating entirely new malware.
The greater risk is operational scale: attackers can produce more believable lures, test more delivery paths, and quickly adjust campaigns when a method fails.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Phishing domain | hxxps://gobf.mx |
CURP campaign phishing page |
| WebDAV domain | onedrive.cv |
WebDAV delivery server |
| File | ReportFinal.RLO.scr |
CURP campaign lure |
| SHA-256 | 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7C2 |
ReportFinal.RLO.scr |
| IP address | 77.110.127.205 |
CURP campaign C2 infrastructure |
| Ports | 56001-56003, 57666, 57777, 57888 |
Associated C2 ports |
| Domain | google.services.ug |
C2 alias/domain |
| Campaign tag | 06x12x2026SantaEbash2 v4.4.3 |
Stealer configuration tag |
| Scheduled tasks | brokerhost, netqueue32 |
Possible persistence artifacts |
| Staging paths | TEMP-XXXXX.tmp-Binary.exe; AppData\i686prod |
CURP campaign staging artifacts |
| C2 endpoint | 23.94.252.228:57666 |
DlrtyGames campaign C2 |
| JA3 | fc54e0d16d9764783542f0146a98b300 |
TLS client fingerprint |
| File | DlrtyGames.exe |
DlrtyGames dropper |
| SHA-256 | e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268 |
DlrtyGames.exe |
| File | discord-rpc.x64.dll |
DLL sideloading component |
| SHA-256 | 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df |
discord-rpc.x64.dll |
| File | profiler16.dll |
Loader component |
| SHA-256 | a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9 |
profiler16.dll |
| File | loader-pool.db |
Image-carried encrypted module container |
| SHA-256 | 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b |
loader-pool.db |
| SHA-256 | 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923 |
.NET RAT payload |
| Staging path | C:\APPDATA\HKCU\appbg\i686\component\v832rc |
DlrtyGames campaign staging artifact |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.