← Back to Crime & Security

Exposed Server Reveals AI-Built Phishing Campaign Targeting Mexican Citizens

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

MEXICO CITY — A Russian-speaking cybercriminal group left a WebDAV delivery server exposed this week, revealing a sophisticated phishing toolkit designed to target Mexican users through fraudulent government identity verification sites. The incident highlights the growing use of generative artificial intelligence in accelerating malware development and deployment.

The compromised infrastructure was discovered on July 20, exposing a comprehensive campaign that utilized AI coding tools known as Coderrr or CodeRRR alongside large language models (LLMs). These automated systems were employed to rapidly write, test, and refine the phishing code. The toolkit mimics official Mexican government portals used for checking identification status, tricking victims into entering sensitive personal data.

Once users interact with these fake sites, the malware initiates a WebDAV hijack technique exploiting known Common Vulnerabilities and Exposures (CVE) to deliver infostealers and ransomware payloads. The attack vector specifically targets Mexican nationals but relies on infrastructure distributed globally through open-source repositories, suggesting an intent for broader scalability.

Security analysts note that the use of AI tools allowed the operators to bypass traditional development bottlenecks. By leveraging generative models, the group could quickly adapt their phishing pages and malware signatures in response to security countermeasures without requiring extensive manual coding expertise. The exposed server contained documentation detailing how the LLMs were prompted to generate polymorphic code variants designed to evade detection by antivirus software.

The campaign represents a shift in cybercriminal operations where artificial intelligence is not merely an aid but a central component of the attack lifecycle. From initial concept to final deployment, AI tools handled the generation of deceptive content and the engineering of exploit chains. The operators appear to have prioritized speed over stealth during the setup phase, leading to the accidental exposure of their command-and-control infrastructure.

While the specific identity of the operator remains unconfirmed, the Russian language used in code comments and configuration files points to a group operating within that linguistic sphere. The exposed toolkit included modules for credential harvesting, session hijacking, and lateral movement across victim networks once access is gained.

Questions remain regarding the total number of victims who may have already interacted with the fraudulent sites before the server was taken offline or secured by researchers. It is also unclear whether other similar campaigns utilizing AI-generated code are currently active against targets in Latin America or elsewhere. The incident underscores an urgent need for government agencies and private sector defenders to update their detection strategies against threats that evolve at machine speed.

Discussion

0 / 2000