Bubble-based Microsoft account phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Threat actors are running an active phishing campaign that abuses Bubble-hosted web apps to evade detection while targeting Microsoft accounts. The setup matters because trusted .bubble.io links can slip past email security controls and deliver victims to fake Microsoft login pages. Stolen credentials may then be used to access Microsoft 365 email, calendar, and other sensitive data.
Related Happenings
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Code of conduct-themed Microsoft AiTM phishing campaign
Campaign
H score53
First: 05.05.2026 09:35
Last: 05.05.2026 09:35
Sources 1
About this happening:
A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...
Code of conduct-themed Microsoft AiTM phishing campaign
CampaignAbout this happening: A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...
FakeWallet crypto wallet phishing campaign targeting users in China
Campaign
H score14
First: 21.04.2026 00:52
Last: 21.04.2026 00:52
Sources 1
About this happening:
The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...
FakeWallet crypto wallet phishing campaign targeting users in China
CampaignAbout this happening: The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...
Latest development: 24.04.2026 14:48
Kaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.
Timeline
-
25.03.2026 21:48 2 articles · 3mo ago
Kaspersky discloses Bubble-hosted Microsoft account phishing
Initial DisclosureKaspersky researchers describe threat actors abusing the no-code platform Bubble to generate and host malicious web apps under *.bubble.io in order to evade phishing detection while targeting Microsoft accounts. The malicious pages use large JavaScript bundles and Shadow DOM-heavy structures to avoid static and automated analysis, then redirect users to fake Microsoft login portals that are sometimes hidden behind a Cloudflare check. Credentials entered on the fraudulent pages can be stolen and used to access Microsoft 365 email, calendar, and other sensitive data.
Show sources
- Bubble AI app builder abused to steal Microsoft account credentials — www.bleepingcomputer.com — 25.03.2026 21:48
- Bubble AI app builder abused to steal Microsoft account credentials — www.bleepingcomputer.com — 25.03.2026 21:48