Find notable cyber news and cases, enriched with sources, timelines, and signals.

Bubble-based Microsoft account phishing campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Threat actors are running an active phishing campaign that abuses Bubble-hosted web apps to evade detection while targeting Microsoft accounts. The setup matters because trusted .bubble.io links can slip past email security controls and deliver victims to fake Microsoft login pages. Stolen credentials may then be used to access Microsoft 365 email, calendar, and other sensitive data.

Related Happenings

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Code of conduct-themed Microsoft AiTM phishing campaign

Campaign
H score53 First: 05.05.2026 09:35 Last: 05.05.2026 09:35 Sources 1

About this happening: A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...

FakeWallet crypto wallet phishing campaign targeting users in China

Campaign
H score14 First: 21.04.2026 00:52 Last: 21.04.2026 00:52 Sources 1

About this happening: The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...

Latest development: 24.04.2026 14:48

Kaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.

Timeline

  1. 25.03.2026 21:48 2 articles · 3mo ago

    Kaspersky discloses Bubble-hosted Microsoft account phishing

    Initial Disclosure

    Kaspersky researchers describe threat actors abusing the no-code platform Bubble to generate and host malicious web apps under *.bubble.io in order to evade phishing detection while targeting Microsoft accounts. The malicious pages use large JavaScript bundles and Shadow DOM-heavy structures to avoid static and automated analysis, then redirect users to fake Microsoft login portals that are sometimes hidden behind a Cloudflare check. Credentials entered on the fraudulent pages can be stolen and used to access Microsoft 365 email, calendar, and other sensitive data.

    Show sources