Skip to content
Phishing Threats Exploit Bubble AI App Builder for Microsoft Credential Theft

Phishing Threats Exploit Bubble AI App Builder for Microsoft Credential Theft

First seen 25 Mar 2026, 20:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 26, 2026 at 19:49 UTC
  • Phishers are using Bubble to create deceptive web apps for credential theft.
  • Legitimate URLs from Bubble evade detection by email security systems.
  • The complexity of the generated code complicates automated threat analysis.

Cybercriminals are leveraging the no-code app-building platform Bubble to create and host malicious web applications that target Microsoft accounts. These phishing campaigns utilize legitimate Bubble-hosted URLs, which evade detection by email security solutions, allowing users to unknowingly access fraudulent login pages. The malicious apps often mimic Microsoft login portals and may include additional checks to bypass security measures. Credentials entered on these fake pages are captured by attackers, potentially compromising sensitive Microsoft 365 data. Kaspersky researchers have noted that the complexity of the generated JavaScript and Shadow DOM structures makes it difficult for automated analysis tools to flag these sites as malicious. This tactic is likely to be adopted by phishing-as-a-service platforms, increasing the stealth of such attacks. The situation is evolving, with security experts urging vigilance against this new method of phishing.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 169d ago How this analysis works

Timeline

2026-03-24
Kaspersky reports on phishing tactics using Bubble.
2026-03-25
BleepingComputer publishes findings on Microsoft account phishing.

More articles in this cluster (2)

Following this threat?

Track Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed