Threat actors are using legitimate and open-weight AI tools to expand phishing, malware delivery, reconnaissance, and fraud operations. Proofpoint observed tens of thousands of malicious Lovable AI website-builder URLs per month in email traffic from February 2025, including pages impersonating Microsoft, UPS, banks, and Aave. Campaigns deployed Tycoon AiTM phishing kits, cryptocurrency wallet drainers, and malware chains involving DOILoader and zgRAT; some sites used CAPTCHA filtering and sent harvested data directly to Telegram. Lovable’s free hosting and remixable public projects enabled rapid cloning of malicious templates, though the provider removed at least one phishing cluster and introduced real-time detection and daily scanning in July 2025.
Recorded Future reported that groups including The Gentlemen ransomware operation have used Chinese AI models for payload generation, analysis, and personally identifiable information triage, while the EvilTokens phishing-as-a-service platform combines AI-generated lures, target research, account validation, and customizable infrastructure intended to evade login-time protections. AI-assisted lures have not consistently outperformed conventional phishing, so layered email and authentication defenses remain effective; however, synthetic media creates a more acute identity threat through executive impersonation, high-value fraud, and biometric-injection attacks capable of defeating live identity-verification checks.

Get the infrastructure and lures behind it.
15 events from the most recent confirmed update back to the earliest known activity.
LexisNexis Risk Solutions reported a 180% year-on-year increase in attacks using deepfake documents, images, and videos designed to imitate a live person.
Z.ai, formerly Zhipu AI, released the GLM-5.2 open-weight model for autonomous AI-agent coding and design tasks. Researchers warned that privately deployed and modified versions could facilitate offensive-code development and vulnerability research, though no real-world attack use was confirmed.
Threat actors reportedly fabricated a Zoom meeting involving Singapore's prime minister, president, government officials, and private-sector representatives, causing a victim to transfer approximately SGD 4.9 million.
EvilTokens emerged as a phishing-as-a-service offering combining AI-generated lures, research functions, account validation, and customizable phishing infrastructure. A documented case showed the service creating fresh sign-in codes and leveraging trusted cloud services and Microsoft's official login page to bypass login-time controls.
Proofpoint reported Lovable abuse involving phishing, fraud, and malware delivery. Lovable linked the report to a credential-phishing cluster and removed a cluster containing hundreds of domains, as well as the reported “ups-flow-harvester” project.
Proofpoint identified a German-language campaign impersonating a German software company that redirected victims to a Lovable-generated download site. A Dropbox-hosted RAR archive used DLL sideloading to execute DOILoader and ultimately zgRAT.
Lovable said it introduced real-time detections and automated daily scanning of published projects to reduce creation of malicious sites.
Proofpoint observed nearly 10,000 SendGrid-delivered emails directing recipients through a Lovable-built page impersonating Aave. Victims were redirected to a fake Aave site that prompted them to connect cryptocurrency wallets, likely to drain assets.
Proofpoint observed nearly 3,500 UPS-themed phishing messages sent through Zoho Forms, using Lovable-hosted pages or redirectors. The counterfeit site collected personal data, card details, and SMS codes and posted stolen data to a Telegram channel.
Proofpoint observed a Tycoon phishing campaign using Lovable URLs and impersonating human-resources departments with employee-benefits lures.
Guardio identified Lovable as a simple and effective platform for criminal abuse, amid growing malicious use of the AI website builder.
Proofpoint identified a file-sharing-themed phishing campaign using Lovable URLs that sent hundreds of thousands of messages and affected more than 5,000 organizations. CAPTCHA-filtered victims were sent to counterfeit Microsoft authentication pages that harvested credentials, MFA tokens, and session cookies using Tycoon AiTM techniques.
Threat actors used deepfake video and synthetic voices to impersonate Arup's CFO and other employees, leading an employee to transfer approximately $25 million.
Recorded Future reported that The Gentlemen ransomware group used Kimi, DeepSeek, Qwen, and HUIHUI-AI models to automate payload generation, technical analysis, and triage of exfiltrated personally identifiable information.
The FBI warned that threat actors had impersonated multiple senior US officials using synthetic voice messages in activity spanning 2023 through 2025.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcerecordedfuture.com
Open sourcez.ai
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.