The exposed lab matters because it shows phishing is being run like software development, not assembled as one-off lures. The operators were testing delivery paths, packaging lures, and keeping the versions that worked, with generative AI helping them generate and document the process.
Rapid7 found more than 1,000 artifacts on a public server used as a malware delivery workspace, including lure files, delivery tests, and notes around WebDAV-based execution. That points to a repeatable pipeline for tuning plausibility and consistency before a campaign goes live.
For defenders, the shift is in preparation. Email filters and user reports still matter, but the other side is now iterating on lure quality and delivery methods before first contact.