ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24054
NTLM Hash Disclosure Spoofing Vulnerability in Microsoft Windows

CVE-2025-24054 is a spoofing vulnerability in Microsoft Windows NTLM caused by external control of a file name or path (CWE-73): when Windows processes a file whose name or path points to an attacker-controlled resource, the system is induced to authenticate via NTLM to that destination, disclosing the user's NTLM hash. An unauthorized network attacker triggers the flaw by convincing a user to interact with a crafted file, for example downloading or opening a malicious file, which sends NTLM credentials to a host of the attacker's choosing. With the captured NTLM hash, the attacker can attempt relay or offline cracking to spoof and impersonate the user on the network; no privileges are required, but user interaction is needed (CVSS 3.1: 5.4, medium). Any unpatched Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), or Windows Server 2008, 2012, 2016, or 2019 system in environments that use NTLM authentication is affected. The flaw is being actively exploited: CISA added it to the KEV catalog on 2025-04-17, EPSS puts the 30-day exploitation probability at about 59% (99th percentile), public proof-of-concept exploits exist, and multiple attack campaigns have been reported, including targeting of organizations in Poland and Romania shortly after the patch became available.

Do: Apply Microsoft's April 2025 security updates across all listed Windows 10, Windows 11, and Windows Server releases and confirm updated builds through patch-management reporting; the flaw was added to CISA's KEV on 2025-04-17, so federal agencies must patch per BOD 22-01 deadlines or apply vendor mitigations. As interim mitigation, restrict outbound NTLM authentication (for example by blocking outbound TCP 445/139 to untrusted hosts, enforcing SMB signing, or removing NTLM where feasible) and hunt for anomalous outbound NTLM authentication following user file downloads or opening of untrusted shortcut files.

5.459% KEV PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
masshundreds of millions of Windows devices (desktops and servers on the affected Windows 10, Windows 11, and Windows Server releases with NTLM in use)
CVE-2025-33053
Remote Code Execution in Microsoft Windows Internet Shortcut Files (CVE-2025-33053)

CVE-2025-33053 is an external control of file name or path flaw (CWE-73) in how Windows processes Internet Shortcut (.url) files, allowing an unauthorized attacker to execute code over a network by making the shortcut resolve to an attacker-controlled path, such as a WebDAV share. Exploitation requires user interaction (CVSS vector UI:R): a user opening a crafted .url file, typically delivered via phishing, causes Windows to fetch and run content from the attacker-specified location, yielding remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All supported Windows 10 and Windows 11 client versions and Windows Server 2008, 2012, 2016, and 2019 are affected. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-10, Microsoft patched it in the June 2025 Patch Tuesday release, and Check Point research tied it to a cyber-espionage campaign by the Stealth Falcon actor against a major Turkish defense organization. EPSS estimates an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's June 2025 security updates to all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts, consistent with the KEV required action and BOD 22-01 timelines for federal agencies. Until patched, consider disabling the Windows WebDAV client where it is not needed and treat unsolicited .url shortcut files as untrusted; given confirmed espionage use, hunt for signs of exploitation on high-value endpoints.

8.888% KEV PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ Windows devices (all listed Windows 10/11 client and mainstream Windows Server releases are affected)
CVE-2026-21513
MSHTML Security Feature Bypass in Windows Exploited in the Wild (CVE-2026-21513)

CVE-2026-21513 is a protection mechanism failure (CWE-693) in Microsoft's MSHTML framework, the legacy HTML rendering engine built into Windows and hosted by browsers, Office, and countless applications that display web content. An unauthorized attacker can exploit it over a network to bypass a Windows security feature; the CVSS vector requires user interaction (UI:R), consistent with delivery via a malicious link or document whose content is rendered through MSHTML. Although classified as a security-feature bypass, the vendor-scored impact is high for confidentiality, integrity, and availability (C:H/I:H/A:H), indicating significant downstream effect when chained with other techniques. All supported Windows client and server releases are in scope, from Windows 10 1607 through Windows 11 25H2 and Windows Server 2012 through Windows Server 2022 23H2. The flaw is being actively exploited: CISA added it to the KEV catalog on 2026-02-10, Microsoft confirmed in-the-wild exploitation, and public reporting ties exploitation to APT28 ahead of the February 2026 Patch Tuesday; EPSS assigns a 15.6% probability of exploitation within 30 days (97th percentile).

Do: Apply Microsoft's February 2026 Windows security updates to all in-scope Windows 10, Windows 11, and Windows Server versions as soon as possible; the flaw is KEV-listed and confirmed exploited in the wild (reporting ties it to APT28), making patching a priority even though ransomware use is not yet confirmed. Because the vector requires user interaction and MSHTML is reached through rendered content, strengthen email and web-lure defenses and hunt for APT28 activity on unpatched hosts; US federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use if mitigations are unavailable.

8.816% KEV
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 21H2
  • +9 more
masshundreds of millions of Windows devices and servers (effectively the entire supported Windows install base, >1 billion devices worldwide)

Indicators of compromiseAll →

TypeIndicatorContext
domaingobf.mxmpaign targeting Mexican users The MDR alert traced back to gobf[.]mx , a typosquat of the government's CURP national-ID lookup
domainsummerartcamp.netlosely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the origina
Full article1,026 words · extracted from thehackernews.com · click to collapse

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.

What makes it more than a payload dump: it caught the operation mid-build. Testing notes, failed experiments, documentation, and live delivery logs sat in one place, the kind of complete development trail defenders rarely see.

Rapid7 reads the artifacts, down to a hardcoded path pointing at an open-source AI coding tool, as an operator using generative AI to produce, test, and document phishing delivery at speed.

The most developed test set focused on CVE-2025-33053 (CVSS 8.8, now in CISA's KEV catalog), the WebDAV working-directory hijack Check Point documented last year in its Stealth Falcon reporting.

The operator appeared to be reproducing it. The technique abuses a .url shortcut to launch a legitimate signed Windows binary while pointing its working directory at an attacker-controlled WebDAV share. In the original attack, the shortcut launched iediagcmd.exe, an Internet Explorer diagnostics tool that starts helpers like route.exe by bare filename; with the working directory pointed at the remote share, Windows loads the attacker's route.exe from WebDAV instead of the real one in System32.

The operator's own README claims this runs with no SmartScreen or Mark-of-the-Web warning, "WITHOUT any security warnings. Zero alerts!" Microsoft patched the flaw in June 2025.

The notes mirror Check Point's writeup closely enough that one recovered README preserved the exact summerartcamp[.]net@ssl@443\DavWWWRoot\OSYxaOjr example path from the original report. Then the operator scaled the testing.

One "comprehensive test kit" expanded the single technique into 59 .url files aimed at other signed binaries: .NET tools like InstallUtil and RegAsm, LOLBAS entries, even UAC-bypass candidates, each with a written theory of why the hijack should work and a tiered testing order.

The notes treat these as candidates to probe one by one, not confirmed hijacks, and the operator built the set for a concrete reason: the original trick breaks on Windows 11 24H2, where Internet Explorer, and so iediagcmd.exe, is gone. The directory also held smaller test sets for two other file-handling flaws, the MSHTML bypass CVE-2026-21513 and the NTLM-leak CVE-2025-24054, but the WebDAV hijack was the main event.

The tell is in the paperwork. Rapid7 says the READMEs, lure-generation guides, matrix-style test write-ups, and a _MAPPING.csv tying each test file to its target binary carry the templated formatting, verbosity, and emoji-heavy structure it associates with LLM output.

It reads the phishing site's emoji-laden JavaScript the same way. The Russian comments and folder names, one called testik (a diminutive of "test"), place the operator in a Russian-speaking context but don't identify them. Rapid7 attributes the operation to an LLM-assisted workflow, likely built with help from Coderrr, which it renders "CodeRRR."

The Hacker News confirmed the repository is public as of July 20, 2026: a general-purpose, open-source AI coding agent inspired by Claude Code, GitHub Copilot CLI, and Cursor, not attacker-specific tooling. Rapid7's summary is blunt: "the attacker used LLMs to operate more like a modern software product team."

The operator even left the delivery panel, an admin tool called Simba Service, sitting on the same server with its default port and credentials unchanged.

An active campaign targeting Mexican users

The MDR alert traced back to gobf[.]mx, a typosquat of the government's CURP national-ID lookup, which served victims a fake record-retrieval page whose download button fired a search-ms: query. That opened the operator's WebDAV share as a Windows Explorer search filtered to .scr files.

The most-delivered lure looked like a CURP PDF report but was a .scr executable, its filename flipped with a right-to-left override to read as a PDF. It was an Inno Setup installer that unpacked a loader and ran a .NET infostealer entirely in memory, hollowed into a signed Qihoo 360 process.

The stealer grabbed cryptocurrency wallets, browser credentials, session cookies, and Telegram sessions. A second campaign directory, DlrtyGames, took a different route, sideloading a trojanized DLL through a signed Ubisoft binary to drop a modular .NET RAT. Rapid7 told The Hacker News that both chains end in the same final payload, the known .NET malware PureRAT.

Over roughly 5.5 days (June 20 to 26, 2026 UTC), the delivery panel logged 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico alone driving 82.5% of traffic and 96.9% of launch activity. A single CURP lure accounted for 2,384 of the 2,441 launch events, about 97.7%.

That figure measures delivery reach, not infections: Rapid7 counts a "launch event" when the panel sees a client request or opens an executable from the share, not a confirmed run on an endpoint, and the traffic from the US and Germany looked more like scanning than victims. The company told The Hacker News it has no visibility into actual infections, so the real compromise count cannot be confirmed. The activity also clustered in Mexican working hours, consistent with real users rather than automated scanners.

For defenders, the June 2025 patch closed the original iediagcmd.exe path, but the 59-file kit shows the operator hunting other signed binaries that behave the same way. Rapid7 has published indicators for both campaigns, including C2 addresses and file hashes, on its GitHub; block those first.

For what the IOCs miss, watch the behavior the alert first caught: the WebClient service starting and davclnt.dll reaching a remote host, a signed binary spawning a child whose image path sits on a WebDAV or UNC share, and filenames using RTLO (U+202E), double extensions, or padding before .exe or .scr.

The delivery burst was short-lived, cooling after June 24. What lasts is the method: an operator wired commodity AI coding tools, never built for the job, into a repeatable pipeline for producing and testing phishing delivery, ready to point at the next target. Rapid7 told The Hacker News it is in the process of notifying CERT-MX.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html