Kuse Web App Abused to Host Phishing Document
Essential information
- Published
- 29/04/2026 21:42
- Modified
- 30/04/2026 07:47
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- ai platform abuse credential harvesting fake login page markdown file phishing social engineering supply chain vendor email compromise
- Tags
- 2026-04-29 ai platform abuse credential harvesting fake login page markdown file phishing social engineering supply-chain vendor email compromise
- Related entities
- 4 indicators, 4 observables, 1 others
Description
Bad actors exploited Kuse, a legitimate AI-based workplace application, to conduct a phishing campaign. Attackers leveraged a Vendor Email Compromise (VEC) to send malicious emails from a trusted vendor's compromised mailbox, establishing initial trust. The attack utilized Kuse's file-sharing features to host a fake blurred document with a Markdown file extension (.md) under the legitimate domain app[.]kuse[.]ai. Victims were presented with a fabricated document preview containing Spanish text prompting them to click a link. This redirected users to a fraudulent Microsoft login page designed to harvest credentials. The attack combined multiple social engineering techniques including domain trust exploitation, unusual file extensions to evade detection, and vendor relationship abuse to bypass security controls and user scrutiny.