Bubble AI app builder abused to steal Microsoft account credentials
嗯,用户让我用中文帮他总结一下这篇文章的内容,控制在一百个字以内。首先,我需要理解文章的主要内容。文章讲的是网络攻击者利用Bubble这个无代码平台生成恶意网页应用,绕过钓鱼检测。因为Bubble是合法平台,邮件安全工具不会标记链接为威胁,导致用户访问恶意页面。 接下来,我得找出关键点:攻击者使用Bubble创建恶意应用,这些应用看起来合法,绕过检测。恶意页面模仿微软登录界面,窃取用户凭证。Bubble生成的代码复杂,难以被静态分析工具识别。 然后,我需要把这些信息浓缩到100字以内。可能的结构是:攻击者利用Bubble生成恶意应用,绕过检测;这些应用模仿微软登录页面;窃取凭证;Bubble代码复杂难检测。 最后,检查是否符合要求:没有使用“文章内容总结”之类的开头,直接描述内容;控制在100字以内。 </think> 网络攻击者利用无代码平台Bubble生成恶意网页应用,绕过钓鱼检测。这些应用托管于合法域名下,欺骗用户访问仿冒微软登录界面的钓鱼页面。输入的凭证被窃取用于非法访问敏感数据。Bubble生成的复杂JavaScript和Shadow DOM结构使恶意代码难以被检测工具识别。 2026-3-25 20:0:18 Author: www.bleepingcomputer.com(查看原文) 阅读量:1 收藏

Bubble AI app builder abused to steal Microsoft account credentials

Threat actors are evading phishing detection in campaigns targeting Microsoft accounts by abusing the no-code app-building platform Bubble to generate and host malicious web apps.

Because the web app is hosted on a legitimate platform, email security solutions do not flag the link as a potential threat, allowing users to access the page.

Security researchers at Kaspersky say that threat actors are using the new method to redirect users to the actual phishing page, which is often mimicking a Microsoft login portal that is sometimes hidden behind a Cloudflare check.

Any credentials entered on these fake web pages are siphoned to the phishing actor, who may then use them to access email, calendar, and other sensitive data associated with Microsoft 365 accounts.

The phishing page
The Microsoft-themed phishing page
Source: Kaspersky

Bubble is a no-code AI-powered platform where users describe the app they want to build and then the platform automatically generates the backend logic and frontend.

The resulting apps are hosted on Bubble’s infrastructure under *.bubble.io, which is a trusted domain unlikely to trigger security warnings from email security solutions.

Phishing actors take advantage of this by creating Bubble apps that consist of large, complex JavaScript bundles and Shadow DOM-heavy structures, which are not flagged as redirection scripts or classified as malicious by static and automated analysis tools.

“The code generated by this no-code platform is a massive jumble of JavaScript and isolated Shadow DOM (Document Object Model) structures,” explains Kaspersky.

“Even for an expert, it’s difficult to grasp what’s happening at first glance; you really have to dig through it to understand how it all works and what the purpose is.”

“Automated web-code analysis algorithms are even more likely to get tripped up, frequently reaching the verdict that this is just a functional, useful site.”

Code fragment of a Bubble app
Code fragment of a Bubble app
Source: Kaspersky

The researchers warn that the tactic of abusing AI-powered app builders for evasion in phishing campaigns is very likely to be adopted by phishing-as-a-service (PhaaS) platforms and integrated into phishing kits that are widely used by lower-tier cybercriminals.

These platforms already provide session cookie theft, adversary-in-the-middle (AiTM) layers that bypass two-factor authentication (2FA), geo-fencing, anti-analysis tricks, and AI-generated email content, so the abuse of legitimate platforms will only increase the stealth of these attacks.

BleepingComputer has contacted Bubble for a comment about Kaspersky’s findings and any plans to strengthen anti-abuse protections, but we have not received a response by publishing time.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/bubble-ai-app-builder-abused-to-steal-microsoft-account-credentials/
如有侵权请联系:admin#unsafe.sh