In this article

Vibe Coding: How AI Tools Are Powering a New Wave of Phishing

Vibe coding lets an attacker describe a phishing site in plain language and get working code back in minutes. This piece walks through how criminals use AI coding platforms to clone login pages, deploy kits at scale, and regenerate code to slip past detection, including a case where a forgotten default favicon exposed the exact tool behind a government impersonation site. It also covers why takedown playbooks built for static domains struggle here.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Published September 3, 2026

kelacyber/vibecodingphishingbanner2x-1788451958013.jpg

Generative coding tools, or vibe coding, are lowering the technical bar for creating malicious infrastructure. Threat actors are using LLMs and code-generation sandboxes to spin up convincing login pages, deploy mass phishing kits, and continuously mutate payloads to avoid detection and takedown. 

KELA’s intelligence is detecting early chatter and emergent “AI-assisted phishing services,” helping defenders find, block, and remove these ephemeral threats faster.

» Ensure your cybersecurity is up to standard with KELA



What is “Vibe Coding”?

Vibe coding refers to natural-language-driven code generation: you describe the site or script you want, and modern developer-focused LLMs and AI sandboxes output working code.

Tools like developer-focused LLMs, cloud code playgrounds, and one-click app scaffolding make it trivial to produce production-ready HTML, server logic, and deployment scripts, often in minutes.

For benign developers, this is productivity. For criminal actors, it’s a shortcut: generate convincing phishing pages, automated deployment scripts, and supporting infrastructure without traditional coding skills.

» Know how to prevent phishing attacks before they catch you



The Exploitation Vector: How Attackers Use Vibe Coding

Attackers are treating generative coding tools like a new kind of toolkit: describe what you want in plain English, and the model spits out production-ready pages, scripts, and deployment commands.

That capability turns previously technical steps, cloning login pages, wiring up credential collectors, and provisioning hosting, into a few simple prompts.

The result is a rapid, repeatable workflow that scales phishing from one-off scams to automated, mass campaigns that can spin up dozens of convincing, short-lived sites in minutes.

» Make sure you understand the most targeted entry points by attackers

1. Clone legitimate login pages

An attacker prompts an AI model to output a near-identical HTML/CSS/JS replica of a bank, cloud provider, or corporate SSO login. The generated page includes a responsive layout, brand-like logos (scraped or re-created), and working form submission code.

2. Automate mass deployment of phishing kits

Natural-language prompts produce not just one page but complete kits: templated pages, phishing form handlers, short-lived hosting/config scripts, and automation to create hundreds of unique subdomains or cloud-hosted instances.

3. Evade detection by on-demand regeneration

Rather than using a static repo, operators regenerate or slightly mutate page code via prompts to the AI sandbox or bot, yielding a new hash, new domain permutations, or slightly different signatures, complicating signature-based detection and manual takedown.

This is not a projection. Proofpoint reported in August 2025 that it had seen tens of thousands of Lovable URLs in malicious detections since February of that year, spanning multi factor authentication phishing kits, cryptocurrency wallet drainers, malware loaders, and kits built to harvest payment card and personal data. Guardio Labs, which published the first VibeScamming benchmark in April 2025, scored Lovable 1.8 out of 10 for resistance to phishing prompts, against 4.3 for Claude and 8 out of 10 for ChatGPT; in Guardio's testing the platform generated a Microsoft sign-in clone, deployed it on its own subdomain, and volunteered an admin dashboard listing captured credentials in plaintext alongside IP addresses and timestamps. Both vendors reported their findings to Lovable, which has said publicly that it does not tolerate malicious use of the platform and has acted on reported cases.

» Looking for a brand protection solution? Look no further than KELA



Vibe Coding Phishing in the Wild

KELA's threat intelligence team has obtained direct evidence of threat actors successfully weaponizing generative coding tools to create malicious assets.

A clear example of this was the discovery of several high-fidelity phishing pages designed to impersonate a government-related agency. These sites were not coded manually but were instead generated using Lovable, a well-known and widely used AI-powered coding platform.

a web page with a red and blue background

Effortless Replication for High-Fidelity Lures

The generative tool enabled the attackers to create a pixel-perfect clone of the legitimate government login page. This capability significantly lowers the technical skill and time required to produce convincing phishing sites, allowing even low-skilled actors to execute sophisticated-looking campaigns at scale.

Classic Attack Chain

The malicious pages, which were designed to steal personal information, were deployed using a classic phishing tactic. They were hosted on newly registered, "lookalike" domains, a technique known as cybersquatting or typosquatting, specifically created to deceive users who might not scrutinize the URL.

» Here's everything you need to know about infostealers

A Critical Attacker Mistake

The most revealing discovery was a significant operational security (OpSec) failure by the attackers. While the visible page was an identical copy of the target, the attackers neglected to change the default favicon (the small icon that appears in a browser's tab). The phishing site's favicon was left as the default "Lovable" logo, providing a direct and unambiguous link between the malicious infrastructure and the specific generative tool used to build it.

This case demonstrates a tangible shift in the threat landscape. Generative AI tools are now demonstrably lowering the barrier to entry for creating the technical assets needed for phishing, moving this capability from the realm of skilled coders to anyone who can write a simple prompt.

The "Lovable" logo mistake highlights that while these tools make creation easier, they do not automatically grant attackers the thoroughness required for a flawless operation.

» Worried about security? Here are the reasons you need cyber threat intelligence

Cybersecurity With KELA

KELA uncovers emerging phishing kits and attacker chatter so you can act before campaigns go live.

Start for FREE
Learn more


Why Takedowns Are Harder Now

Traditional takedown playbooks rely on static domains, central hosting, and human-managed control panels. Vibe-coded phishing complicates that model:

  • Dynamically generated: pages are created on demand and often exist for short windows.
  • Hosted on legitimate cloud or AI sandbox environments: pages run inside bona fide developer sandboxes or PaaS accounts, raising friction for takedown teams and sometimes requiring cloud provider escalation.
  • Difficult to trace or attribute: automated generation, ephemeral hosting and reseller services together create noisy attribution trails and reduce the evidence tying a page to its operator. None of that makes removal impossible, but it does change what a removal request has to look like. KELA Brand Control submits formal takedown requests to domain registrars, hosting providers, social platforms and app stores, and most are resolved within hours. Where a domain is malicious, it can also be submitted to browser protection services such as Google Safe Browsing and Microsoft SmartScreen, so users are warned off the site while the infrastructure takedown is still in progress, or if it fails. That second path matters more than usual against short-lived pages, because it does not depend on the host answering the phone. One constraint is worth stating plainly: a domain cannot be taken down purely for resembling a brand. Evidence of malicious use, or a clear intellectual property violation, has to come with the request. For a vibe-coded page that goes dark in a few hours, that means capturing the evidence while the page is still up.

» Did you know? Cybercriminals now exploit generative AI



How Exposure Intelligence Helps Defenders

KELA collects raw data from hacking forums, illicit markets and Dark Net communities, and from the instant messaging services threat actors actually use, mainly Telegram and Discord. Searching that data for terms like "AI phishing", prompt templates or service listings is often the earliest indicator of a new trend, and a saved query can be set to email an analyst the moment new matches appear. Alongside that, Brand Control watches for the infrastructure side: look-alike domains registered against a brand, including typo-squatting and subdomain spoofing, and live phishing sites built to mimic that brand.

» Find out how agentic AI is transforming cybersecurity



Detection Signals Defenders Should Watch For

Security/IR Teams Can Look For:

  • Clusters of newly registered or short-lived domains resolving to cloud sandbox IPs.
  • HTML/JS that contains identical content but with different resource names or obfuscated strings, a pattern indicative of rapid templating.
  • Email or forum chatter advertising “AI phishing templates,” “one-click clones,” or “SSO page generator.”
  • Rapidly rotated form endpoints (same visual page, different submission URIs).
  • Unusual volumes of inbound credentials to low-reputation webhooks or collector endpoints hosted on developer sandboxes.

The key point is that the skill barrier moved, not the attack. Credential phishing still works the way it always has; what changed is that building the lure no longer filters out the people who cannot code, and the infrastructure now disappears faster than a manual takedown cycle can chase it.

» Ready to begin? Contact us to learn more or try KELA for free

Stay One Step Ahead

KELA gives you clear, real-time insight into new phishing infrastructure and tactics.

Contact Us

FAQ: Vibe Coding Phishing

What is vibe coding phishing?

Vibe coding phishing is the use of natural-language AI coding tools to build phishing infrastructure. Instead of writing HTML and server code, an attacker describes the page they want, and the platform returns working code and in some cases deploys it automatically on a subdomain it controls. The technique matters because it removes the coding skill that used to filter out low-capability actors.

Which AI tools have been abused this way?

Lovable is the most widely documented case. Guardio Labs scored it lowest of the platforms it benchmarked for resistance to phishing prompts in April 2025, and Proofpoint reported tens of thousands of Lovable URLs in malicious detections from February 2025 onward. Reporting has also covered similar abuse of other AI site builders, and Lovable has stated that it does not tolerate malicious use and acts on reported cases.

How can you tell a phishing page was generated by an AI coding tool?

Look for artifacts the operator did not think to change. A default favicon belonging to the coding platform is the clearest example, and it is what exposed one government impersonation campaign our team examined. Other signals include pages hosted on a coding platform's own subdomains, clusters of short-lived domains resolving to the same sandbox infrastructure, and pages that are visually identical while their resource names and form submission endpoints keep rotating.

Why are AI-generated phishing sites harder to take down?

They are built on demand, often live for only hours, and frequently run inside legitimate developer sandboxes or platform-as-a-service accounts, which means removal can require escalation to a cloud provider rather than a straightforward registrar request. Speed of detection matters more than usual, because a takedown request has to carry evidence of malicious use, and that evidence has to be captured while the page is still up.



Related Articles

Token Hijack: The Drift-Salesforce Breach that Shook SaaS

Token Hijack: The Drift-Salesforce Breach that Shook SaaS

KELA Cyber Intelligence Center

September 9, 2025

KELA Cybercrime Update: August 2025 Snapshot

KELA Cybercrime Update: August 2025 Snapshot

KELA Cyber Intelligence Center

September 18, 2025