How the Rise of AI ‘Vibe Coding’ Introduced a New Phishing Shortcut for Cybercriminals

|

|

Reddit logo
A screenshot displaying Netcraft's newly updated dashboard with a cleaner user experience.

Type a sentence and get a working website. That's the promise behind "vibe coding," the AI-assisted development trend that enables users to generate websites and applications from natural-language prompts.

While these tools have opened software development to a broader audience, Netcraft's research shows they've also lowered the barrier to entry for cybercriminals building phishing infrastructure. 

Luke Wood, Netcraft’s global infrastructure partnerships lead, appeared on the Openprovider Podcast earlier this year to talk through what's actually happening on these platforms.  

The same features that make vibe coding appealing to legitimate builders — speed, zero technical barrier, low-cost or free options — are exactly what's making it appealing to fraudsters. 

No code, no design skills, no problem 

Vibe coding, a term coined by one of the co-founders of OpenAI in early 2025, describes an AI-assisted development process where a person prompts a LLM to generate a functional website or app on their behalf. The people using these tools often have no coding or design background at all. 

That same low barrier applies to sign-up. Netcraft's investigation into a handful of these platforms found inconsistent Know Your Customer (KYC) checks across the board. Some ask for nothing more than an email address, and while several mainstream platforms have caught on to obvious anonymous-inbox services like 10 Minute Mail, most still accept free webmail accounts like Gmail or Proton Mail, and that’s often good enough for an attacker who just needs a throwaway identity to start building. 

Most vibe-coding platforms also run prompt-based content filters designed to stop someone from generating something like a Netflix phishing page outright. In practice, those filters are inconsistent.  

“During our analysis at Netcraft, we were able to generate two functional pages with minimal difficulty which cloned a well-known postal delivery service and a well-known streaming service,” Wood said during the podcast appearance. “These pages even had functional credential stores when credentials were inputted into the login page.” 

(These builds were never published; they were internal testing only.) 

One vibe coding platform Netcraft tracks was fielding fewer than 250 reports a month in January 2025, according to Wood. By October 2025, that number had passed 4,000 a month.  

A separate platform integrated with Netcraft's free provider-based API tells a similar story: Wood says it saw roughly 10 attacks using AI-based tools a month a year ago, growing to more than 1,500 in March 2026. 

The rapid growth in abuse reflects a broader shift in phishing operations. Activities that previously required technical skills, phishing kits, or access to criminal marketplaces can now be performed through consumer-facing AI tools with little to no development experience. 

Vibe coding is a better deal than renting a phishing kit 

For years, the path of least resistance for a low-skill fraudster was a phishing-as-a-service (PhaaS) subscription — kits like Darcula or Lighthouse that charge a monthly fee for pre-built templates. But those types of attacker tools come with strings attached like payment trails, recurring charges, and a financial relationship that gives law enforcement something to follow. 

Vibe coding platforms skip all of that. Most offer generous free tiers, and a fraudster who burns through the limit on one account can just spin up another with a fresh throwaway email.  

“Browsers can simply spin up multiple accounts to effectively bypass these limits or even utilize [store-bought pre-paid] cards to pay for the subscription services,” Wood said. “Some of the solutions we looked at have a simple option to just clone the generated page that the fraudster could use, allowing them to easily spin up further attacks using that one cloned page they've generated.” 

The most concerning shift Wood said Netcraft has seen is the precision with which these tools can create convincing phishing pages.  

Rather than trying to send out a massive volume of spam emails pretending to be a well-known consumer brand, fraudsters are increasingly using vibe coding to clone the login pages of platforms that sit behind the brands people recognize like human resources software, benefits portals employees access at work, and third-party vendors that a company's employees trust implicitly, but the general public may have never heard of. 

“Determining if a website has been generated with AI is not an exact science. What often happens when utilizing a vibe-coding solution is that a free subdomain is created upon the generation of a website,” Wood said. “For example, my[-]website[.]vibeproject[.]app. When [there is no sub-domain], an AI-generated website can look like any other website on the surface.” 

Crypto scams get a multi-stage AI upgrade 

Netcraft has also tracked a large-scale campaign targeting cryptocurrency holders for several years, and according to Wood, vibe coding has slotted neatly into its existing playbook.  

The attack typically opens with a slickly built AI-generated lure site, then routes the victim through additional steps toward the actual phishing page — often distributed using SEO manipulation, where compromised WordPress plugins are abused to plant fake comments on well-known websites that link back to the phishing infrastructure. 

The end goal is one of two things: the victim's cryptocurrency exchange login or their cryptocurrency wallet's seed phrase — the master key that lets anyone regain access to a crypto wallet. Some of these pages go a step further and attempt to intercept two-factor authentication codes in real time to get past that layer of defense too. 

Netcraft has been able to confirm AI involvement in a number of these pages through an ironic tell: leftover AI prompt text baked right into the fraudulent site, sometimes including warnings from the LLM about the risks of phishing that the AI generated as a safety measure. 

What this means for registrars, hosts, and everyone downstream 

For domain registrars, hosting providers, and anyone building online experiences on behalf of clients, this shift changes how defenders need to think about phishing risk. Wood said he expects the trend toward highly targeted attacks to extend further into infrastructure providers themselves: registries, resellers, hosting companies, and their downstream customers. These attacks look more professional than the phishing most people have learned to recognize, and that professionalism is precisely what makes them harder for the average user to catch. 

“Users should just remain vigilant and question the source of the URL they are visiting,” Wood said. “How they gain access to the site is a key question. Did they receive it in an email, SMS, phone call, etc.? Do they trust the validity of the outreach? Have they got questions about it? Is it a sense of urgency? If so, they really should question the validity of that outreach and that URL specifically.” 

If something looks off, report it. Anyone can submit a suspicious site they see in the wild for free at report.netcraft.com. Those reports feed Netcraft's detection pipeline, which is ingested by major browsers and antivirus vendors and can trigger a takedown — Netcraft's median takedown time currently sits at 33 minutes. Vibe coding may let a fraudster stand up a convincing phishing page in minutes, but the takedown side of that equation has gotten just as fast. 

“Whilst [attackers] can spin up those sites in a matter of minutes, we can also get them taken down in a matter of seconds, helping protect the end user of the internet against these phishing attacks and other AI-based closed attack-based methods,” Wood said. 

The same AI tools that make web development more accessible are also reducing the technical barriers that once slowed phishing operations. As these platforms continue to evolve, organizations, infrastructure providers, and end users should expect phishing campaigns to become increasingly professional, scalable, and targeted. 

Related

Related

Related

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.