2 Sources
[1]
AI website builder Lovable increasingly abused for malicious activity
Cybercriminals are increasingly abusing the AI-powered Lovable website creation and hosting platform to generate phishing pages, malware-dropping portals, and various fraudulent websites. The malicious sites created through the platform impersonate large and recognizable brands, and feature traffic filtering systems like CAPTCHA to keep bots out. While Lovable has taken steps to better protect its platform from abuse, as AI-powered site generators increase in number, the barrier to entering cybercrime continues to drop. Since February, cybersecurity company Proofpoint "observed tens of thousands of Lovable URLs" that were delivered in email messages and were flagged as threats. In a report today, the researchers describe four malicious campaigns that abused the Lovable AI website builder. One example is a large-scale operation that relied on the phishing-as-a-service platform known as Tycoon. Emails contained Lovable-hosted links that opened with a CAPTCHA and then redirected users to fake Microsoft login pages featuring Azure AD or Okta branding. These sites harvested user credentials, multi-factor authentication (MFA) tokens, and session cookies through adversary-in-the-middle techniques. During the campaigns, the threat actor sent hundreds of thousands of messages to 5,000 organizations. A second example was a payment and data theft campaign that impersonated UPS, sending nearly 3,500 phishing emails with links that directed victims to phishing sites. The sites asked visitors to enter personal details, credit card numbers, and SMS codes, which were then sent to a Telegram channel controlled by the attacker. The third is a cryptocurrency theft campaign that impersonated the DeFi platform Aave, sending out close to 10,000 emails via SendGrid. Targeted users were led to Lovable-generated redirects and phishing pages designed to trick them into connecting their wallets, likely followed by asset drainage. The fourth case concerns a malware delivery campaign distributing the remote access trojan zgRAT. Emails contained links that led to Lovable apps posing as invoice portals, which delivered RAR archives hosted on Dropbox. The files included a legitimate signed executable alongside a trojanized DLL that launched DOILoader, ultimately loading zgRAT. Lovable introduced real-time detection of malicious site creation in July, and also automatically scans published projects daily to spot and delete any fraud attempts. The developer also stated that it plans to introduce additional protections this fall, which would proactively identify and block abusive accounts on the platform. Guardio Labs confirmed to BleepingComputer that Lovable can still be used to create malicious sites. In a recent test, the researchers generated a fraudulent site to impersonate a large retailer and encountered no objection from the platform. BleepingComputer has contacted Lovable to ask about the effectiveness of the existing anti-abuse measures on the platform, but a comment wasn't immediately available.
[2]
Top AI website builder Lovable hit in worrying cyberattack - here's what we know
Lovable is introduction different protections to combat the threat Lovable, a popular AI website builder which allows users to craft quality websites by talking to the platform, is being heavily abused in different cybercriminal activities, experts have warned. Security researchers at Proofpoint have revealed how, since February 2025, they have seen "tens of thousands" of Lovable URLs used in malicious campaigns, being distributed through phishing emails. "Cybercriminals are increasingly using an AI-generated website builder called Lovable to create and host credential phishing, malware, and fraud websites," Proofpoint said in its report. The company added it has observed, "numerous campaigns leveraging Lovable services to distribute multifactor authentication (MFA) phishing kits like Tycoon, malware such as cryptocurrency wallet drainers or malware loaders, and phishing kits targeting credit card and personal information." Ever since the emergence of the first ChatGPT version, security researchers have been warning about AI tools lowering the barrier for entry into cybercrime. At first, threat actors used Generative AI to craft convincing phishing emails, or write malware code quickly and efficiently. However, since website builders started integrating AI as well, criminals found a new toy to play with. In February 2025 alone, Proofpoint claims to have seen a campaign leveraging file sharing themes to distribute credential phishing, which included "hundreds of thousands of messages" and impacted more than 5,000 organizations. Fortunately, Lovable isn't sitting with its hands crossed. One credential phishing cluster with hundreds of domains was taken down by Lovable the same week it was reported. The company also told Proofpoint it recently implemented AI-driven security protections to make building phishing sites impossible, including real-time detections to prevent creation of malicious websites as users prompt the tool, and automated daily scanning of published projects to flag potentially fraudulent projects.
Share
Copy Link
Cybercriminals are increasingly abusing Lovable, an AI-powered website creation platform, to generate phishing pages and malicious websites. The company is implementing new security measures to combat this threat.
Lovable, an AI-powered website creation and hosting platform, has become a target for cybercriminals who are increasingly exploiting its capabilities to generate phishing pages, malware-dropping portals, and fraudulent websites. Security researchers at Proofpoint have observed "tens of thousands of Lovable URLs" being used in malicious campaigns since February 2025, highlighting the growing concern over AI tools lowering the barrier for entry into cybercrime 12.
Source: Bleeping Computer
The abuse of Lovable's platform has been significant, with Proofpoint reporting multiple large-scale operations:
These malicious sites often feature sophisticated elements such as traffic filtering systems like CAPTCHA to evade detection and maintain their effectiveness 12.
The cybercriminals behind these campaigns employ various strategies to maximize their success:
In light of these abuses, Lovable has taken steps to enhance the security of its platform:
However, the effectiveness of these measures remains in question. Guardio Labs reported to BleepingComputer that they were still able to create a fraudulent site impersonating a large retailer without objection from the platform 1.
Source: TechRadar
The exploitation of AI-powered tools like Lovable for malicious purposes underscores a growing concern in the cybersecurity community. As AI-powered site generators become more prevalent, there is a risk that the barrier to entering cybercrime will continue to drop 12.
This trend highlights the need for ongoing vigilance and adaptation in the face of evolving cyber threats. It also emphasizes the importance of responsible AI development and the implementation of robust security measures in AI-powered tools to prevent their misuse by malicious actors.
As the situation continues to evolve, it remains crucial for both users and developers of AI-powered platforms to stay informed about potential risks and take proactive steps to enhance security.
Summarized by
Navi
[1]
NVIDIA CEO Jensen Huang confirms the development of the company's most advanced AI architecture, 'Rubin', with six new chips currently in trial production at TSMC.
2 Sources
Technology
22 hrs ago
2 Sources
Technology
22 hrs ago
Databricks, a leading data and AI company, is set to acquire machine learning startup Tecton to bolster its AI agent offerings. This strategic move aims to improve real-time data processing and expand Databricks' suite of AI tools for enterprise customers.
3 Sources
Technology
22 hrs ago
3 Sources
Technology
22 hrs ago
Google is providing free users of its Gemini app temporary access to the Veo 3 AI video generation tool, typically reserved for paying subscribers, for a limited time this weekend.
3 Sources
Technology
14 hrs ago
3 Sources
Technology
14 hrs ago
Broadcom's stock rises as the company capitalizes on the AI boom, driven by massive investments from tech giants in data infrastructure. The chipmaker faces both opportunities and challenges in this rapidly evolving landscape.
2 Sources
Technology
22 hrs ago
2 Sources
Technology
22 hrs ago
Apple is set to introduce new enterprise-focused AI tools, including ChatGPT configuration options and potential support for other AI providers, as part of its upcoming software updates.
2 Sources
Technology
22 hrs ago
2 Sources
Technology
22 hrs ago