Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Bubble AI app builder abused to steal Microsoft account credentials
    Cybersecurity

    Bubble AI app builder abused to steal Microsoft account credentials

    adminBy adminMarch 26, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Bubble AI app builder abused to steal Microsoft account credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Bubble AI app builder abused to steal Microsoft account credentials

    Threat actors are evading phishing detection in campaigns targeting Microsoft accounts by abusing the no-code app-building platform Bubble to generate and host malicious web apps.

    Because the web app is hosted on a legitimate platform, email security solutions do not flag the link as a potential threat, allowing users to access the page.

    Security researchers at Kaspersky say that threat actors are using the new method to redirect users to the actual phishing page, which is often mimicking a Microsoft login portal that is sometimes hidden behind a Cloudflare check.

    Any credentials entered on these fake web pages are siphoned to the phishing actor, who may then use them to access email, calendar, and other sensitive data associated with Microsoft 365 accounts.

    The phishing page
    The Microsoft-themed phishing page
    Source: Kaspersky

    Bubble is a no-code AI-powered platform where users describe the app they want to build and then the platform automatically generates the backend logic and frontend.

    The resulting apps are hosted on Bubble’s infrastructure under *.bubble.io, which is a trusted domain unlikely to trigger security warnings from email security solutions.

    Phishing actors take advantage of this by creating Bubble apps that consist of large, complex JavaScript bundles and Shadow DOM-heavy structures, which are not flagged as redirection scripts or classified as malicious by static and automated analysis tools.

    “The code generated by this no-code platform is a massive jumble of JavaScript and isolated Shadow DOM (Document Object Model) structures,” explains Kaspersky.

    “Even for an expert, it’s difficult to grasp what’s happening at first glance; you really have to dig through it to understand how it all works and what the purpose is.”

    “Automated web-code analysis algorithms are even more likely to get tripped up, frequently reaching the verdict that this is just a functional, useful site.”

    Code fragment of a Bubble app
    Code fragment of a Bubble app
    Source: Kaspersky

    The researchers warn that the tactic of abusing AI-powered app builders for evasion in phishing campaigns is very likely to be adopted by phishing-as-a-service (PhaaS) platforms and integrated into phishing kits that are widely used by lower-tier cybercriminals.

    These platforms already provide session cookie theft, adversary-in-the-middle (AiTM) layers that bypass two-factor authentication (2FA), geo-fencing, anti-analysis tricks, and AI-generated email content, so the abuse of legitimate platforms will only increase the stealth of these attacks.

    BleepingComputer has contacted Bubble for a comment about Kaspersky’s findings and any plans to strengthen anti-abuse protections, but we have not received a response by publishing time.


    tines

    Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

    Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

    abused Account app Bubble Builder Credentials Microsoft steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle’s releasing Google-Agent: Here’s what to know
    Next Article No way! Amazon is basically handing you $100 back on the Galaxy S26 right now
    admin
    • Website

    Related Posts

    WordPress 7.0 Could Trigger Rush To Steal AI API Keys

    May 22, 2026

    Microsoft Clarity Now Shows Grounding Queries Behind AI Citations

    May 22, 2026

    Microsoft plans significant update to Windows Secure Boot

    May 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google expands Data Manager API with GMP event ingestion

    June 2, 2026

    The 50 Most-Cited Websites in Copilot (June 2026)

    June 2, 2026

    What Google’s New AI Guide Actually Debunks. And What It Doesn’t

    June 2, 2026

    Broadcom, Samsung team for wireless SoC

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,333)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (322)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google expands Data Manager API with GMP event ingestion

    June 2, 2026

    The 50 Most-Cited Websites in Copilot (June 2026)

    June 2, 2026

    What Google’s New AI Guide Actually Debunks. And What It Doesn’t

    June 2, 2026
    Most Popular
    • Google expands Data Manager API with GMP event ingestion
    • The 50 Most-Cited Websites in Copilot (June 2026)
    • What Google’s New AI Guide Actually Debunks. And What It Doesn’t
    • Broadcom, Samsung team for wireless SoC
    • What it means for your marketing strategy in 2026
    • DV360 API Adds Demand Gen Support
    • The 50 Most-Cited Websites in Grok (June 2026)
    • Can Chinese memory maker CXMT help relieve the memory shortage?
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.