AI-Powered Website Builder Lovable Exploited for Cybercriminal Activities

2 Sources

Share

Cybercriminals are increasingly abusing Lovable, an AI-powered website creation platform, to generate phishing pages and malicious websites. The company is implementing new security measures to combat this threat.

AI-Powered Website Builder Exploited for Cybercrime

Lovable, an AI-powered website creation and hosting platform, has become a target for cybercriminals who are increasingly exploiting its capabilities to generate phishing pages, malware-dropping portals, and fraudulent websites. Security researchers at Proofpoint have observed "tens of thousands of Lovable URLs" being used in malicious campaigns since February 2025, highlighting the growing concern over AI tools lowering the barrier for entry into cybercrime

1

2

.

Source: Bleeping Computer

Source: Bleeping Computer

Scope of the Threat

The abuse of Lovable's platform has been significant, with Proofpoint reporting multiple large-scale operations:

  1. A phishing-as-a-service campaign using the Tycoon platform sent hundreds of thousands of messages to over 5,000 organizations, impersonating Microsoft login pages

    1

    .
  2. A payment and data theft operation mimicking UPS targeted nearly 3,500 individuals

    1

    .
  3. A cryptocurrency theft campaign impersonating the DeFi platform Aave sent approximately 10,000 emails

    1

    .
  4. A malware delivery campaign distributing the zgRAT remote access trojan

    1

    .

These malicious sites often feature sophisticated elements such as traffic filtering systems like CAPTCHA to evade detection and maintain their effectiveness

1

2

.

Cybercriminal Tactics

The cybercriminals behind these campaigns employ various strategies to maximize their success:

  1. Brand Impersonation: The malicious sites created through Lovable often impersonate large, recognizable brands to lend credibility to their schemes

    1

    .
  2. Multi-Factor Authentication (MFA) Bypassing: Some phishing kits are designed to harvest not only user credentials but also MFA tokens and session cookies through adversary-in-the-middle techniques

    1

    2

    .
  3. Cryptocurrency Targeting: Campaigns specifically aimed at cryptocurrency users attempt to trick victims into connecting their wallets, potentially leading to asset drainage

    1

    .

Lovable's Response

In light of these abuses, Lovable has taken steps to enhance the security of its platform:

  1. Implementation of real-time detection of malicious site creation in July 2025

    1

    .
  2. Daily automated scanning of published projects to identify and delete fraud attempts

    1

    .
  3. Plans to introduce additional protections in the fall to proactively identify and block abusive accounts

    1

    .

However, the effectiveness of these measures remains in question. Guardio Labs reported to BleepingComputer that they were still able to create a fraudulent site impersonating a large retailer without objection from the platform

1

.

Broader Implications

Source: TechRadar

Source: TechRadar

The exploitation of AI-powered tools like Lovable for malicious purposes underscores a growing concern in the cybersecurity community. As AI-powered site generators become more prevalent, there is a risk that the barrier to entering cybercrime will continue to drop

1

2

.

This trend highlights the need for ongoing vigilance and adaptation in the face of evolving cyber threats. It also emphasizes the importance of responsible AI development and the implementation of robust security measures in AI-powered tools to prevent their misuse by malicious actors.

As the situation continues to evolve, it remains crucial for both users and developers of AI-powered platforms to stay informed about potential risks and take proactive steps to enhance security.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo