Home Cyber Security News Hackers Use GenAI to Build WebDAV Malware Lab Delivering PureRAT and Credential...

Hackers Use GenAI to Build WebDAV Malware Lab Delivering PureRAT and Credential Stealers

0
GenAI WebDAV Lab Delivers Malware
GenAI WebDAV Lab Delivers Malware

Security researchers have uncovered an exposed WebDAV server operating as a malware testing and delivery lab, rather than a simple payload-hosting site.

The infrastructure contained more than 1,000 files used to test phishing lures, shortcut abuse, Windows execution paths, and payload delivery chains leading to PureRAT and credential-stealing malware.

The discovery began after MDR telemetry detected a user launching a file from a WebDAV location through rundll32.exe. Investigators observed the Windows WebClient service starting and davclnt.dll contacting a remote server, which led them to the exposed directory.

The server held 1,048 artifacts, including 453 malicious LNK launchers, 236 filename-spoofing tests, 146 URL and LOLBin execution experiments, 89 encrypted droppers, WebDAV scripts, ClickFix pages, payload stubs, and attacker documentation.

The scale and organization suggest the operator treated malware delivery like a software-development workflow.

Snippet of one of many subfolders containing testing files (Source: rapid7)
Snippet of one of many subfolders containing testing files (Source: rapid7)

GenAI WebDAV Lab Delivers Malware

The actors appear to have used generative AI to produce structured READMEs, test matrices, lure-generation guides, scripts, and documentation for their WebDAV administration panel.

Several files included highly formatted instructions, emoji-heavy comments, bilingual text, detailed testing steps, and explanations of Windows execution behavior patterns often associated with LLM-assisted content generation.

The lab tested Windows delivery mechanisms including WebDAV shares, UNC paths, search-ms: URIs, .library-ms files, Control Panel items, trusted Windows binaries, PowerShell download cradles, mshta, certutil, and bitsadmin.

It also used RTLO characters, Unicode spoofing, double extensions, whitespace padding, and fake document icons. It minimized execution windows to make malicious files appear legitimate.

One major test set focused on CVE-2025-33053, a Windows Internet Shortcut issue involving working-directory abuse.

The technique can invoke a legitimate binary such as iediagcmd.exe while setting an attacker-controlled WebDAV share as its working directory.

Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic (Source: rapid7)
Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic (Source: rapid7)

If the application launches child processes by name, Windows may resolve those binaries from the remote WebDAV location instead of expected local paths.

The operator expanded this concept into a 59-file test kit targeting .NET utilities, LOLBins, system binaries, and potential UAC-bypass candidates.

The exposed files showed the actor experimenting with InstallUtil, RegAsm, RegSvcs, ngentask, CustomShellHost, OfficeC2RClient, fodhelper, and other Windows components.

The most active campaign impersonated Mexico’s CURP national identity lookup service through the typosquatted domain gobf[.]mx.

Victims were presented with a fraudulent government-style portal and prompted to retrieve an alleged identity document.

Instead of delivering a PDF, the phishing site triggered a search-ms: URI that opened a remote WebDAV share containing .scr files.

The primary lure, ReportFinal.rcs.pdf, was not a PDF but an RTLO-masqueraded Windows screensaver executable.

Indicators of Compromise

IOC TypeIndicatorContext
Phishing domaingobf[.]mxTyposquatted Mexican CURP-themed phishing site
Legitimate impersonated sitegob[.]mx/curp/Official CURP service impersonated by the campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here