Security researchers at Rapid7 have pulled back the curtain on how modern phishing operations are built, after discovering an exposed server containing 1,048 files tied to a live campaign targeting victims in Mexico. The find links an AI-assisted phishing pipeline directly to malware delivered through WebDAV, a protocol most people have never heard of but that attackers increasingly rely on to sneak malicious files past defenses.

The discovery matters less because of the number of victims and more because of what it reveals: a working blueprint of how generative AI tools are now embedded into the phishing supply chain, from lure creation to payload delivery.

What Rapid7 Found on the Exposed Server

According to Rapid7's research, the exposed server was not locked down the way an operational attacker infrastructure should be. That misconfiguration let researchers collect 1,048 files, effectively a snapshot of the toolkit an operator was using to run an active phishing and malware campaign aimed at targets in Mexico.

Exposed command-and-control or staging servers are not unusual in the threat intelligence world. Attackers make mistakes just like defenders do, and when they leave a server open, researchers get a rare look at the machinery behind a campaign rather than just its aftermath. In this case, that machinery included evidence of an AI-assisted phishing pipeline, meaning the operators were using large language model tools somewhere in the process of building or refining their lures.

Inside the AI-Assisted Phishing Pipeline

The use of AI in phishing is not a new theory; it has become a documented pattern across multiple campaigns this year. What makes the Rapid7 findings notable is the direct link between an LLM-assisted content pipeline and a functioning malware delivery chain built on WebDAV, rather than just isolated examples of AI-generated phishing emails.

This mirrors a broader shift documented across the industry. Campaigns like VENOMOUS#HELPER, which compromised more than 80 U.S. organizations using legitimate remote monitoring and management tools, showed how attackers increasingly lean on trusted, everyday technology to avoid detection. AI-assisted content generation fits the same logic: it lets attackers produce convincing, well-written, localized lures at scale without needing native language fluency or heavy manual effort, lowering the skill barrier for running a credible campaign.

Why WebDAV Is the Delivery Mechanism of Choice

WebDAV (Web Distributed Authoring and Versioning) is a protocol that lets users manage and edit files on a remote web server, similar to a shared network drive accessed over HTTP. Because it's built into Windows and widely used in legitimate business settings, traffic to WebDAV servers doesn't always raise red flags the way an unfamiliar executable download might.

That familiarity is exactly what makes it attractive to attackers. A malicious file hosted on a WebDAV share can be referenced in a phishing email or document in a way that looks like routine file access, helping the payload slip past users and, in some cases, security tooling that isn't tuned to scrutinize WebDAV connections closely.

This fits a pattern seen across the year's major incidents. As Verizon's 2026 Data Breach Investigations Report noted, software flaws have overtaken passwords as the top breach entry point, but social engineering and trusted-protocol abuse remain critical companion tactics that get attackers past the first line of defense before any technical exploit comes into play.

What This Means For You

If you're in Mexico or work with organizations that operate there, this campaign is a direct reminder to treat unexpected file-sharing links and login prompts with suspicion, even when they look polished and professional. AI-assisted phishing content is specifically designed to eliminate the grammatical and tonal mistakes that used to be a reliable warning sign.

For everyone else, the broader lesson is that phishing kits are evolving faster than most individual users' instincts for spotting them. The rundown of major cyberattacks of 2026 shows a consistent theme: attackers are professionalizing their tooling, often faster than the organizations defending against them can adapt their training and detection.

Actionable Takeaways

  • Be wary of unexpected file-sharing or document links, even if the email or message looks well-written and legitimate.
  • Verify unusual requests to open shared files through a second channel, such as a phone call or a separate messaging app, before clicking.
  • Keep endpoint security and email filtering tools updated, since WebDAV-based delivery can bypass defenses tuned only for common attachment types.
  • Businesses should audit which protocols, including WebDAV, are allowed through their network and restrict access where it isn't operationally necessary.
  • Stay informed about how AI-assisted phishing techniques are evolving, since the polish and personalization of lures will likely keep improving.

The exposed server Rapid7 uncovered offers a rare, concrete look at how AI tools are being folded into real-world phishing operations rather than staying a theoretical risk. Understanding how these AI-assisted phishing campaigns are built is the first step toward recognizing them before they succeed.