THREAT OPS › Threat News › From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
<h2 style="direction: ltr;">Executive summary</h2><p style="direction: ltr;"><span style="font-size: undefined;">An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths,
Attributed threat actors
- Stealth FalconG0038
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Archive via UtilityT1560.001
- Screen CaptureT1113
- KeyloggingT1056.001
- Encrypted/Encoded FileT1027.013
- IP AddressesT1590.005
- JavaScriptT1059.007
- Steal Web Session CookieT1539
- Double File ExtensionT1036.007
- Bypass User Account ControlT1548.002
- Malicious FileT1204.002
- InstallUtilT1218.004
- DLLT1574.001
- Automated CollectionT1119
- Clipboard DataT1115
- Native APIT1106
- Data from Local SystemT1005
- Deobfuscate/Decode Files or InformationT1140
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- Reflective Code LoadingT1620
- Time Based ChecksT1497.003
- Control PanelT1218.002
- Archive Collected DataT1560
- Credentials from Web BrowsersT1555.003
- Right-to-Left OverrideT1036.002
- Windows Management Instrumentation Event SubscriptionT1546.003
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- Registry Run Keys / Startup FolderT1547.001
- Hijack Execution FlowT1574
- Process HollowingT1055.012
- Encrypted ChannelT1573
- CredentialsT1589.001
- SteganographyT1027.003
- Web Session CookieT1550.004
- Obtain CapabilitiesT1588
- Debugger EvasionT1622
- Dynamic API ResolutionT1027.007
- Develop CapabilitiesT1587
- SteganographyT1001.002
- COR_PROFILERT1574.012
- Obtain CapabilitiesAML.T0016
- Software ToolsAML.T0016.001
- Generative AIAML.T0016.002
- Develop CapabilitiesAML.T0017
- Data from Local SystemAML.T0037
- LLM Prompt CraftingAML.T0065
- MasqueradingAML.T0074
Indicators of compromise
- 04a8018191f2e9e76072d072a933371d9d669a42de2b2a087541cd3a653b0ba7sha256
- e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268sha256
- 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645dfsha256
- a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9sha256
- 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93bsha256
- 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923sha256
- fc54e0d16d9764783542f0146a98b300md5
- CVE-2025-33053cve
- CVE-2026-21513cve
- CVE-2025-24054cve
- https://www.gob.mx/curp/url
- https://gobf.mxurl
- 77.110.127.205ipv4
- 23.94.252.228ipv4
- images.contentstack.iodomain
- chatgpt.comdomain
- summerartcamp.netdomain
- relaypayments.comdomain
- link.comdomain