This popular app builder has been hijacked to steal Microsoft account information – here’s what we know


  • Cybercriminals abuse Bubble.io no-code platform to host phishing apps
  • Trusted Domain Bypasses Email Security and Fools Victims of Microsoft 365 Credential Theft
  • Kaspersky warns that techniques are likely to spread via phishing-as-a-service kits, making attacks more dangerous

Cybercriminals have been seen abusing a legitimate AI app building platform to bypass email security protections and land phishing emails straight into people’s inboxes.

Security researchers Kaspersky identified the affected program as Bubble.io, a no-code visual programming platform that allows users to create entire web and mobile apps without writing a single line of code. However, this means that hackers can also use the drag-and-drop editor or an AI chatbot to generate complex JavaScript and frontend structure, embed malicious functionality, and host the site on the bubble.io domain.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top