SECURITY·중요도 8·2026. 07. 20.·The Hacker News

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

── KO ──────────────────

AI를 활용한 피싱 툴킷이 드러난 사건에 대한 분석.

해커들이 웹DAV를 이용한 피싱 캠페인을 위한 AI 도구를 공개하였습니다. Rapid7은 공격자의 서버에서 발견된 1,048개의 파일을 수집했으며, 이는 라이브 캠페인에서도 사용된 것으로 나타났습니다. 이 도구는 윈도우 사용자를 대상으로 정부 ID 조회 사이트를 위장하여 인포스틸러를 배포하는 방식으로 작동합니다.


── EN ──────────────────

AI-assisted phishing toolkit uncovered following exposed server incident.

A malware operator's exposed server revealed an AI-assisted phishing toolkit comprising 1,048 files. Rapid7 analyzed the contents, which included lure templates and execution methods, uncovering a live campaign targeting Windows users in Mexico. This campaign delivered an infostealer via a spoofed government ID-lookup site using WebDAV techniques.

원문 보기 →목록으로