← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 20, 2026 · 13:00via Rapid7 Blog

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Brief

Executive summary

An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.

Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.

This incident underscores the imperative of preemptive security.

Read more on Rapid7 Blog