AI-Labeled Phishing Pipeline Is Already in Production

The break is not a single phishing kit. The exposed server showed a reusable delivery pipeline with lure templates, test notes, and built variants, which means the operator can keep refining and redeploying the same approach instead of burning one-off lures. Rapid7 recovered 1,048 files and tied them to an active WebDAV infostealer campaign against Windows users in Mexico. The set included testing records and campaign materials, and the main test set focused on CVE-2025-33053, the WebDAV working-directory hijack used to make a signed Windows binary load a malicious helper from a remote share. That changes the read on the campaign. The risk is not just the payload already seen in the wild; it is the production process behind it, with generative-AI-assisted content creation folded into phishing delivery so the operator can iterate faster and reuse the same abuse path across campaigns.

Part of the PlainSec briefing for 2026-07-21

Sources