logo

Bubble AI app builder abused to steal Microsoft account credentials

ID: 8eb309eb-626a-5f1f-a335-6dd26bb59452

STIX ID: report--8eb309eb-626a-5f1f-a335-6dd26bb59452

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-03-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky and reporting show threat actors are using Bubble’s legitimate no-code app hosting to serve heavily obfuscated Microsoft-themed phishing pages on trusted *.bubble.io domains, allowing credential harvesting and evasion of email security; researchers warn this tactic — which leverages complex JavaScript and Shadow DOM to hide redirection and data exfiltration — is likely to be integrated into phishing-as-a-service kits and increase the stealth and scale of account takeover campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.