Rapid7 Alert Reveals GenAI Malware Factory
A recent alert by Rapid7 has revealed a GenAI-powered malware factory crafted by threat actors to create over 1,000 attack files. This unexpected exposure on a WebDAV server provided insights into how these actors assemble, test, and distribute malicious software. Attackers targeted Windows users with deceptive documents and phishing lures exploiting WebDAV and file explorer vulnerabilities. The Rapid7 alert reveals generative AI usage in streamlining operations, such as creating phishing content and testing delivery methods. This activity predominantly involved shortcut launchers, file-spoofing tests, and encrypted droppers, evidenced by over 77,000 requests from across 101 countries, primarily Mexico. Analysts observed techniques including CVE-2025-33053 exploitation, aiming to disguise malicious files as routine documents. Organizations should prioritize monitoring abnormal WebDAV activities. By scaling operations, attackers increase campaign effectiveness, necessitating vigilance. For more details on this development, access the full article here:
One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
