BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover
BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling (TL-2026-0828), also tracked as BlueKit, is a high-severity phishing campaign, first published 2026-06-16 and last reviewed 2026-08-29. It is attributed to BlueKit operators with low confidence, affects Google Gmail / Google Ads / Google Passkey, maps to 28 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0828
- Threat ID
- TL-2026-0828
- Also known as
- BlueKit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-06-16
- Last reviewed
- 2026-08-29
- Attribution
- BlueKit operators
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, fintech, cryptocurrency, cloud services, e-commerce, enterprise saas, developer infrastructure, brokerage, social media
- Target regions
- North America, Europe, Canada, India, East Asia
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-08-29 · revalidated 1× · latest source
Malware and tooling in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
Malware and tooling: Abliterated Llama (safety-filter-removed), CapSolver, NanoGPT, Octo Browser
BlueKit is a commercial, subscription-based Phishing-as-a-Service platform offering 87 ready-made phishing kits across email, cloud, social, banking, brokerage, e-commerce, and cryptocurrency brands. It bundles adversary-in-the-middle (AiTM) session hijacking, WebAuthn/passkey capture, hardware-wallet seed-phrase harvesting, smishing, and AI-assisted lure generation into a single dashboard, lowering the technical barrier for full account takeover.
How BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling works
BlueKit is a mature, commercially optimized Phishing-as-a-Service (PhaaS) ecosystem documented by CloudSEK TRIAD (June 17, 2026) and independently analyzed by Varonis Threat Labs (April 30, 2026). It consolidates the entire phishing attack lifecycle — domain registration and provisioning, realistic credential-harvesting page hosting, campaign delivery, real-time data exfiltration, and automated post-compromise actions — into a single web dashboard sold under a crypto-only, duration-based subscription with a reseller/affiliate (white-label) program.
The platform ships 87 ready-made phishing kits (Varonis observed 40+ at an earlier development stage) impersonating high-value brands across email/cloud (Google, Microsoft, Proton, Yahoo, Zoho, Apple iCloud/Apple ID, Dropbox, OneDrive, AWS), social media (Twitter/X, Meta/Facebook, Instagram, WhatsApp, TikTok, Discord, LinkedIn, Reddit, Telegram), developer infrastructure (GitHub, NPM, RubyGems, PyPI), authentication/SSO (LastPass, Okta, Citrix, Evernote), banking (PayPal, Wells Fargo, Bank of America, Fifth Third, BNC National, Atlantic Union, iQ Credit Union, Intuit/QuickBooks, TD Bank, EQ Bank, Orange France), brokerage (Robinhood, SoFi, Questrade, Trading 212), cryptocurrency exchanges (Binance, Coinbase, Coinspot, Bybit, MEXC, OKX, KuCoin, Crypto.com, Gate, Upbit, TradeZero), and hardware wallets (Ledger and Trezor firmware-update lures designed to harvest 24-word recovery seed phrases).
BlueKit's core advantage is adversary-in-the-middle (AiTM) session hijacking: it captures not only credentials but also cookies, local storage, and live session state, enabling MFA/2FA bypass via session-token replay through the integrated Octo Browser anti-detect browser. It additionally captures and stores WebAuthn credential material to undermine passwordless/passkey authentication. Automated post-compromise modules add the attacker as a Google Ads administrator, drive Google/Microsoft passkey enrollment, change passwords, and resolve Amazon 2FA — converting a single harvested login into durable, attacker-controlled account access.
The platform integrates CapSolver (CAPTCHA solving), NanoGPT and multiple LLMs (including an 'abliterated' safety-filter-removed Llama, plus GPT-4.1, Claude, Gemini, and DeepSeek as offered model options) for multilingual lure generation, and a peer-to-peer page-rendering architecture to obscure backend infrastructure. Operators receive real-time victim notifications via Telegram, with Jabber/XMPP, Session Protocol, and PGP for operator communications. Granular evasion controls include VPN/proxy blocking, headless/user-agent filtering, fingerprint-based filters, Cloudflare phishing-check and Safe Browsing bypass, cloaking, anti-bot filtering, selective crawler evasion, and per-site country bans (CIS-country targeting is explicitly prohibited per configuration). A leaked/exposed backend revealed five tables: Mammoths (victim credentials, FTS-indexed), Customers (operators, Argon2id password hashes), Sites_settings (per-site proxy/country/script configs), Webauthn_credentials, and Deposits (crypto payments with transaction hashes and HD-wallet derivation indices). As of the Varonis report no confirmed live campaign had been observed, but frequent active development indicates imminent operational deployment.
MITRE ATT&CK techniques used in TL-2026-0828
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1656 Impersonation; T1665 Hide Infrastructure
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1573 Encrypted Channel
Initial Access
T1078 Valid Accounts; T1566 Phishing
Persistence
T1098 Account Manipulation; T1556 Modify Authentication Process
Collection
T1185 Browser Session Hijacking
Lateral Movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Impact
stealth
Affected products and versions in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
- Google — Gmail / Google Ads / Google Passkey
Vulnerable versions: all (credential/session theft via impersonation) - Microsoft — Outlook / Live / Office 365
Vulnerable versions: all (credential/session theft via impersonation) - Apple — iCloud / Apple ID
Vulnerable versions: all (credential/session theft via impersonation) - Ledger — Hardware Wallet (firmware-update lure)
Vulnerable versions: all (seed-phrase social engineering) - Trezor — Hardware Wallet (firmware-update lure)
Vulnerable versions: all (seed-phrase social engineering) - Multiple — 87 impersonated brands (banking, crypto exchanges, brokerage, SSO, developer registries)
Vulnerable versions: all (AiTM MFA bypass via session-cookie theft)
Remediation for BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
Immediate actions
- Block BlueKit clearnet domains (bluekit.ws, bluekit.cc, bluekit.su, bluekit.pk) and the Tor onion service at perimeter and DNS resolvers
- Hunt for AiTM session-cookie replay: flag sessions where authentication and subsequent API use originate from different IPs/ASNs/geographies or anti-detect browser fingerprints
- Invalidate and rotate active sessions for any user who interacted with a suspected lure; force re-authentication
- Alert on suspicious Google Ads administrator additions, passkey/WebAuthn enrollments, and password changes immediately following a login from a new location
Workarounds
- Restrict crypto hardware-wallet firmware updates to vendor-native apps only; never enter seed phrases into any web page
- Disable legacy/SMS MFA in favor of phishing-resistant factors
- Geo/ASN-based step-up authentication for sensitive actions
Longer-term hardening
- Deploy phishing-resistant FIDO2/WebAuthn hardware authenticators bound to origin (device-bound passkeys resist AiTM relay)
- Enforce token binding / continuous access evaluation and short-lived sessions to limit cookie-replay value
- Deploy conditional access requiring managed/compliant devices for high-value applications
- Brand-impersonation monitoring and rapid takedown for the 87 targeted brands; user security-awareness training on AiTM and firmware-update seed-phrase lures
Weaknesses (CWE) in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
CWE-1021, CWE-290, CWE-384, CWE-451, CWE-522
Timeline of BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
- BleepingComputer reports on the new Bluekit phishing service, highlighting its AI assistant for multilingual lure generation and roughly 40 ready-made brand templates.
- Varonis documents an exposed Bluekit backend revealing the operating model: a crypto-only, duration-based subscription with a white-label reseller program, Octo Browser anti-detect integration for session replay, CapSolver CAPTCHA solving, and automated post-compromise modules (Google Ads admin addition, passkey enrollment, password change, Amazon 2FA resolution).
- Varonis Threat Labs publishes the first public analysis of the Bluekit all-in-one PhaaS platform, observing 40+ brand templates, an integrated AI assistant (abliterated Llama plus GPT-4.1/Claude/Gemini/DeepSeek options), and adversary-in-the-middle (AiTM) cookie/session capture; the platform is assessed as under active development with no confirmed live campaign yet.
- Hackread, eBuilder Security, and Ciphers Security amplify the findings, emphasizing Bluekit's MFA-bypass session hijacking, WebAuthn/passkey targeting, and Telegram-based real-time credential exfiltration.
- TechRadar reports that Bluekit can bypass enterprise 2FA protocols and emulate 40+ global brands through point-and-click campaign tooling, framing it as a low-skill barrier to scalable account takeover.
- Threadlinqs Intelligence ingests BlueKit as an active PhaaS threat for IOC blocking and AiTM/session-replay detection engineering.
- Clearnet domains, the Tor onion service, Cloudflare nameservers (fish/osmar.ns.cloudflare.com) and Web Analytics token, the internal platform identifier, and Luxhost (Dominican Republic) hosting attribution are disclosed for detection and blocking.
- CloudSEK details the exposed five-table backend — Mammoths (FTS-indexed victim credentials), Customers (operators with Argon2id hashes), Sites_settings (per-site proxy/country/script configs with CIS-country bans), Webauthn_credentials, and Deposits (multi-coin crypto payments with HD-wallet derivation indices) — confirming platform maturity and affiliate compartmentalization.
- CloudSEK TRIAD publishes a deep dark-web investigation documenting the matured platform: 87 phishing kits (up from the 40+ Varonis observed), clearnet (bluekit.ws/.cc/.su/.pk) and Tor infrastructure, Octo Browser/CapSolver/NanoGPT integration, WebAuthn capture, hardware-wallet (Ledger/Trezor) seed-phrase lures, a smishing module, HD-wallet crypto payments, and a reseller program.
- Netcraft identifies BlueKit's shift to an rrweb-based Browser-in-the-Middle (BitM) technique — streaming a real, remotely-controlled attacker browser DOM to the victim over WebSocket so authentication completes on attacker infrastructure and yields a fully valid session — reported by BleepingComputer.
Update history for TL-2026-0828
- 2026-08-29 — BlueKit: Commercial Phishing-as-a-Service Platform with 87 Ready-Made Kits, Session-Cookie MFA Bypass, and Automated Account Takeover: What changed Severity/exploitability/status unchanged (HIGH/ACTIVE/ACTIVE). Netcraft (via BleepingComputer, 2026-06-25) documents BlueKit's technique evolution from AiTM cookie-relay to an rrweb-based Browser-in-the-Middle (BitM) approach t
Sources cited for BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
- BlueKit Phishing-as-a-Service (PhaaS)
- Meet Bluekit: The AI-Powered All-in-One Phishing Kit
- New Bluekit phishing service includes an AI assistant, 40 templates
- New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks
- Researchers discover new all-in-one Bluekit phishing kit capable of bypassing enterprise 2FA protocols
- Bluekit Phishing Kit Turns Session Hijacking into a Point-and-Click Operation
- Bluekit Phishing Kit Bundles AI Assistant And 40 Templates For Scalable Campaigns
Threats related to BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling
Detection coverage for TL-2026-0828
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0828 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.