A recently uncovered exposed server has revealed a sophisticated malware delivery lab, containing over 1,000 artifacts and functioning as a quality assurance hub for attackers to test delivery paths, social engineering lures, and WebDAV execution methods. This lab demonstrates a significant shift in adversary operations, with attackers leveraging generative AI, such as large language models (LLMs), to generate social engineering lures at scale, allowing them to operate like modern software development teams. The use of AI enables attackers to move beyond individual exploits and test various delivery methods, including WebDAV, to optimize their malware campaigns. This level of sophistication and use of AI-powered tools indicates a significant escalation in the threat landscape1. The existence of such a lab matters to security practitioners because it highlights the increasing complexity and scale of modern malware delivery operations, requiring them to adapt their defenses to keep pace with these evolving threats.