THREATOPS
THREAT OPSThreat News › From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

medrapid7Published 2026-07-20

<h2 style="direction: ltr;">Executive summary</h2><p style="direction: ltr;"><span style="font-size: undefined;">An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths,

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis