PULSE NAME
IOC - Kuse Web App Abused to Host Phishing Document
WHITE celestre 2026-04-30 Modified: 2026-05-30
4
IOCs
LOW VOLUME
As AI increases its role in work and daily life, AI apps are also increasing in number. Along with this emergence are expanding attack vectors that threat actors are actively exploring. AI is reshaping the cybersecurity landscape, introducing both unprecedented opportunities and complex risksnews article. On April 9, 2026, the TrendAI Managed Services Team encountered a phishing attack that revealed another vulnerability that enabled attackers to store phishing chains, breach trust, and eventually expose credentials. In this case, attackers abused the storage and sharing features of Kuse, a free AI web app.
Indicators of Compromise (2 / 4 total)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://app.kuse.ai/sharednote/ 2026-04-30
URL https://onlineapp.ooraikaoo.info/?auth2=8rf22euu-2nxkebabDjjILlzldhQq2Pz 2026-04-30