BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover — Threadlinqs Intelligence
As of 2026-06-16, BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover is a high-severity phishing threat attributed to BlueKit operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0828 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: BlueKit operators · FINANCIAL
BlueKit is a commercial, subscription-based Phishing-as-a-Service platform offering 87 ready-made phishing kits across email, cloud, social, banking, brokerage, e-commerce, and cryptocurrency brands.
BlueKit is a mature, commercially optimized Phishing-as-a-Service (PhaaS) ecosystem documented by CloudSEK TRIAD (June 17, 2026) and independently analyzed by Varonis Threat Labs (April 30, 2026). It consolidates the entire phishing attack lifecycle — domain registration and provisioning, realistic credential-harvesting page hosting, campaign delivery, real-time data exfiltration, and automated post-compromise actions — into a single web dashboard sold under a crypto-only, duration-based subscription with a reseller/affiliate (white-label) program.
The platform ships 87 ready-made phishing kits (Varonis observed 40+ at an earlier development stage) impersonating high-value brands across email/cloud (Google, Microsoft, Proton, Yahoo, Zoho, Apple iCloud/Apple ID, Dropbox, OneDrive, AWS), social media (Twitter/X, Meta/Facebook, Instagram, WhatsApp, TikTok, Discord, LinkedIn, Reddit, Telegram), developer infrastructure (GitHub, NPM, RubyGems, PyPI), authentication/SSO (LastPass, Okta, Citrix, Evernote), banking (PayPal, Wells Fargo, Bank of America, Fifth Third, BNC National, Atlantic Union, iQ Credit Union, Intuit/QuickBooks, TD Bank, EQ Bank, Orange France), brokerage (Robinhood, SoFi, Questrade, Trading 212), cryptocurrency exchanges (Binance, Coinbase, Coinspot, Bybit, MEXC, OKX, KuCoin, Crypto.com, Gate, Upbit, TradeZero), and hardware wallets (Ledger and Trezor firmware-update lures designed to harvest 24-word recovery seed phrases).
BlueKit's core advantage is adversary-in-the-middle (AiTM) session hijacking: it captures not only credentials but also cookies, local storage, and live session state, enabling MFA/2FA bypass via session-token replay through the integrated Octo Browser anti-detect browser. It additionally captures and stores WebAuthn credential material to undermine passwordless/passkey authentication. Automated post-compromise modules add the attacker as a Google Ads administrator, drive Google/Microsoft passkey enrollment, change passwords, and resolve Amazon 2FA — converting a single harvested login into durable, attacker-controlled account access.
The platform integrates CapSolver (CAPTCHA solving), NanoGPT and multiple LLMs (including an 'abliterated' safety-filter-removed Llama, plus GPT-4.1, Claude, Gemini, and DeepSeek as offered model options) for multilingual lure generation, and a peer-to-peer page-rendering architecture to obscure backend infrastructure. Operators receive real-time victim notifications via Telegram, with Jabber/XMPP, Session Protocol, and PGP for operator communications. Granular evasion controls include VPN/proxy blocking, headless/user-agent filtering, fingerprint-based filters, Cloudflare phishing-check and Safe Browsing bypass, cloaking, anti-bot filtering, selective crawler evasion, and per-site country bans (CIS-country targeting is explicitly prohibited per configuration). A leaked/exposed backend revealed five tables: Mammoths (victim credentials, FTS-indexed), Customers (operators, Argon2id password hashes), Sites_settings (per-site proxy/country/script configs), Webauthn_credentials, and Deposits (crypto payments with transaction hashes and HD-wallet derivation indices). As of the Varonis report no confirmed live campaign had been observed, but frequent active development indicates imminent operational deployment.
Weaknesses (CWE)
CWE-1021, CWE-290, CWE-384, CWE-451, CWE-522
Target sectors: financial, banking, fintech, cryptocurrency, cloud services, e-commerce, enterprise saas, developer infrastructure, brokerage, social media
Target regions: North America, Europe, Canada, India, East Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1587, T1588, T1608, T1566, T1566, T1566, T1056, T1539