Malware · 56 days ago
The exposed lab matters because it shows phishing is being run like software development, not assembled as one-off lures. The operators were testing delivery paths, packaging lures, and keeping the versions that worked, with generative AI helping them generate and document the process.
Rapid7 found more than 1,000 artifacts on a public server used as a malware delivery workspace, including lure files, delivery tests, and notes around WebDAV-based execution. That points to a repeatable pipeline for tuning plausibility and consistency before a campaign goes live.
For defenders, the shift is in preparation. Email filters and user reports still matter, but the other side is now iterating on lure quality and delivery methods before first contact.
1 source covering this story
Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation
An MDR alert recently led the Rapid7 team to an exposed server acting as a fully operational malware delivery lab.
Part of the PlainSec briefing for 2026-07-20