Rapid7 discovered an exposed malware delivery server containing over 1,000 files that revealed a mid-development phishing operation targeting Windows users in Mexico, using a WebDAV working-directory hijack (CVE-2025-33053) to deliver an infostealer disguised as a government ID document. The exposed toolkit showed strong evidence of AI-assisted development, with LLM-formatted documentation, test matrices, and emoji-heavy code suggesting the operator used an open-source AI coding agent to rapidly build, test, and scale the campaign. Over roughly five and a half days the panel logged over 77,000 requests, with Mexico accounting for the vast majority of traffic, and both identified campaign chains ultimately delivered the known .NET malware PureRAT.