heroui logo

Service abuse: Lovable-hosted redirect to external phishing page

Sublime Rules

View Source
Summary
Detects inbound emails that contain links pointing to Lovable-hosted sites (lovable.app published sites or lovableproject.com preview/sandbox builds) whose rendered target pages include links to external domains or raw IP addresses. The rule requires lure-text in the email body prompting actions such as viewing, opening, accessing, or downloading documents, invoices, payments, voicemail, or similar items. This pattern signals abuse of the Lovable platform as an intermediary to redirect victims to credential phishing or other malicious destinations. Detection is triggered when the email body links resolve to Lovable-hosted domains and the final landing page exposes external destinations (IPs or non-Lovable domains) or when the link text matches common lure phrases. The rule flags Credential Phishing attempts that chain an open redirect through a free subdomain host. It leverages URL analysis (domain/IP checks), HTML analysis (final DOM links), and content analysis (lure text) to identify this abuse.
Categories
  • Endpoint
  • Web
  • Network
Data Sources
  • Network Traffic
Created: 2026-10-06