Source: www.proofpoint.com – Author:
Cybercriminals are increasingly using the AI-driven website builder Lovable to rapidly create and host fraudulent sites for phishing, malware delivery, and financial scams, according to cybersecurity researchers at Proofpoint.
Research conducted by Tommy Madjar, Selena Larson, and the Proofpoint Threat Research Team shows that Lovable’s ease of use has significantly lowered barriers for criminal activity in the cyber domain. The AI-powered platform allows users to generate fully functioning websites from simple text prompts, making it straightforward to replicate legitimate brand websites and set up complex phishing schemes.
“We are often asked about the impact of AI on the threat landscape. While we have observed that large language model (LLM) generated emails or scripts have little impact, some AI tools are lowering the barrier for entry for digital crime. Take, for example, services that can create websites in minutes with the help of AI,” commented the researchers.
According to Proofpoint, Lovable has become a popular choice among threat actors, who use it not only to build credential harvesting sites but also to distribute malware such as cryptocurrency wallet drainers and orchestrate fraud, including scams targeting personal and financial information through impersonation of well-known brands.
Low entry barriers
Lovable markets itself as a user-friendly tool enabling people to create and deploy websites simply by describing their ideas in natural language. The service also includes free hosting via the lovable[.]app domain, with the free version allowing users to generate up to five full websites per day. While paid accounts can hide the platform’s branding and use custom domains, free accounts display a visible “Edit with Lovable” badge and allow public remixing.
Proofpoint observed that these features, intended to drive ease of use, have inadvertently facilitated malicious activity. Its researchers succeeded in crafting fake sites that imitated prominent enterprise software, built with deceptive functionality for credential theft, without encountering any technical barriers or ethical safeguards from the AI platform.
“Cybercriminals are increasingly using an AI-generated website builder called Lovable to create and host credential phishing, malware, and fraud websites. Proofpoint has observed numerous campaigns leveraging Lovable services to distribute multifactor authentication (MFA) phishing kits like Tycoon, malware such as cryptocurrency wallet drainers, and phishing kits targeting credit card and personal information,” the research team reported.
Aside from email campaigns, Lovable URLs have been detected in SMS-based threats, including those relating to investment scams and banking credential phishing, reflecting the tool’s reach across multiple attack vectors.
Types of campaigns observed
Since February 2025, Proofpoint has identified tens of thousands of Lovable-created URLs per month in email threat data. Among the key observations are the following:
- Tycoon Phishing-as-a-Service kits have been delivered through file-sharing or HR-themed Lovable sites. Attack flows commonly include initial CAPTCHAs to filter responses, followed by fake Microsoft authentication pages aimed at harvesting credentials and multi-factor authentication tokens via Adversary-in-the-Middle techniques.
- Scams impersonating UPS in June 2025 used Lovable-hosted pages to harvest address, credit card, and SMS code information from victims. Gathered data was then posted to Telegram channels. Similar banking credential theft campaigns used the platform’s remixable template features.
- Malicious campaigns targeting cryptocurrency holders involved Lovable-based clones of decentralised finance sites like Aave. These prompted victims to connect their digital wallets, resulting in automatic drainage of cryptocurrency funds.
Lack of guardrails
Researchers found that Lovable’s lack of restrictions enables even novice users to craft fully functional, deceptive sites containing backend scripting, phishing kits, and manipulative language within a matter of minutes.
“In June of 2025, researchers easily created fully functional phishing sites with backend logic and deceptive language using just one or two prompts. Unlike other AI services (e.g., ChatGPT), Lovable does not refuse to assist with malicious code or manipulative language, highlighting a lack of recognition for potential abuse. According to Lovable, their security updates will cut back on this type of abuse,” the Proofpoint team stated.
Researchers suggest that the rapid creation and hosting of phishing and malware sites, which previously required specialised web development skills and time investments, can now be accomplished by criminals with minimal technical expertise using tools like Lovable.
Some AI tools significantly lower the barrier for cybercriminals by simplifying the creation of believable social engineering content. Historically, this required significant time and web development knowledge. With automatic web creation tools, threat actors can focus more on attack chains and incorporate AI-generated social engineering. Creators of such tools must implement safeguards to prevent exploitation. Organisations should consider allow-listing policies for frequently abused tools.
Original Post URL: https://www.proofpoint.com/us/newsroom/news/ai-website-builder-lovable-fuels-rise-phishing-scams
Category & Tags: –
Views: 3