الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky has discovered a new corporate phishing technique using a popular AI web development platform

Kaspersky has discovered a new corporate phishing technique using a popular AI web development platform
June 10, 2026
Kaspersky has discovered that attackers have begun exploiting another legitimate service for malicious purposes – this time it is Tencent EdgeOne Pages, a platform for creating and hosting web applications. Attackers are misusing its capabilities to generate phishing emails targeting corporate users. Previously Kaspersky has described similar attacks leveraging Google services and web applications generated by Bubble, an AI-powered app builder, to hunt for corporate credentials.
Employees across multiple industries including the industrial sector, sales, and government are among the targets. The goal of the attack is to steal login credentials for corporate resources. Over the past 30 days, the company’s experts have detected more than 8,000 phishing emails using this tactic, including messages in English, Korean, and Russian.
The Tencent EdgeOne Pages service is positioned as a platform for quickly creating and deploying web applications using AI. Scammers misuse it to generate and publish phishing pages in minutes with virtually no web development skills.
Attackers host phishing pages on EdgeOne’s legitimate cloud infrastructure and use trusted domains. As a result, such sites appear to be established and secure to many protective solutions, complicating the detection of such attacks.
How the attack begins
The user receives an email from the alleged “corporate email support team”. The message states that the account login credentials will expire in 48 hours, and that failure to update them may result in problems receiving or sending emails. To avoid restrictions, the user is prompted to click a link and enter relevant information. Phishing emails are not limited to this narrative, and could deliver any corporate message, such as a message from the HR department or a notification of a received document that should be downloaded.
Clicking the link in the email opens a page with a form for entering the victim’s name, email address, and password. It is a simple design, with virtually no additional elements.

A page that was set up by the attackers to collect credentials
After the user enters their login and password, the data is transferred to a server controlled by the attackers.
“We are seeing a continuation of the trend in which attackers use AI and no-code platforms as part of their phishing infrastructure. We’ve previously observed a similar scheme using the Bubble platform, and here we have yet another example. While the communication used in these phishing attacks is typical and has been used before multiple times, the attack technique itself significantly lowers the barrier to entry for attackers and accelerates the creation of phishing resources. Previously this required at least basic web development skills, but now an infrastructure for fraudulent emails can be created in minutes,” comments Roman Dedenok, Anti-Spam Expert at Kaspersky.
To be protected, Kaspersky recommends:
• Educate employees so that they understand that corporate credentials should only be entered on verified, official company platforms.
• Deploy robust security solutions to block access to known and suspicious phishing destinations.
• Implement advanced anti-phishing technologies at the email gateway to reduce exposure to malicious messages.
• Stay updated on evolving attacker techniques and integrate threat intelligence into security operations.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
اورنچ مصر ووادي دجلة تطلقان منظومة حلول ذكية بــ«نيو» في مستقبل سيتي أورنچ مصر وهواوي تطلقان أول تجربة عالمية لتقنية CCIC على شبكات الميكروويف بنك saib يرفع العائد على شهادة Excellence الثلاثية إلى 18.25% كوربوريت ستاك تنفذ مشروعًا لرقمنة 1000 مصنع بالتعاون مع مركز تحديث الصناعة الذكاء الاصطناعي في الفصول الدراسية.. كيف يتخيل الجيل Z مستقبل التعليم؟ ڤاليو تنجح في إتمام إصدار سندات توريق بقيمة 945.8 مليون جنيه إم إن تي-حالاࣧ تنجح فى إتمام مجموعة من إصدارات سندات التوريق بقيمة تتجاوز 4 مليار جنيه بنهاية الربع ... تنميه تتعاون مع«ايسكور»و«سينابس أناليتكس»لتطوير قرارات الائتمان بالذكاء الرقمي مع هيونداي توسان.. راحة بالك تمتد لـ3 سنوات أو 60 ألف كيلومتر مع باقة الصيانة الخاصة من جي بي أوتو قمة الابتكار الجامعي 2026 تعلن الفرق الفائزة بمشاركة 100 مشروع من 30 جامعة سالي سلامة أمام الاختبار الأصعب في نيسان مصر.. هل تعود الثقة من بوابة العميل والأمان؟ محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية