BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover

BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling (TL-2026-0828), also tracked as BlueKit, is a high-severity phishing campaign, first published 2026-06-16 and last reviewed 2026-08-29. It is attributed to BlueKit operators with low confidence, affects Google Gmail / Google Ads / Google Passkey, maps to 28 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-0828

Threat ID
TL-2026-0828
Also known as
BlueKit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-16
Last reviewed
2026-08-29
Attribution
BlueKit operators
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial, banking, fintech, cryptocurrency, cloud services, e-commerce, enterprise saas, developer infrastructure, brokerage, social media
Target regions
North America, Europe, Canada, India, East Asia
Detection rules
9
Indicators of compromise
27
Updates
2026-08-29 · revalidated 1× · latest source

Malware and tooling in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

Malware and tooling: Abliterated Llama (safety-filter-removed), CapSolver, NanoGPT, Octo Browser

BlueKit is a commercial, subscription-based Phishing-as-a-Service platform offering 87 ready-made phishing kits across email, cloud, social, banking, brokerage, e-commerce, and cryptocurrency brands. It bundles adversary-in-the-middle (AiTM) session hijacking, WebAuthn/passkey capture, hardware-wallet seed-phrase harvesting, smishing, and AI-assisted lure generation into a single dashboard, lowering the technical barrier for full account takeover.

How BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling works

BlueKit is a mature, commercially optimized Phishing-as-a-Service (PhaaS) ecosystem documented by CloudSEK TRIAD (June 17, 2026) and independently analyzed by Varonis Threat Labs (April 30, 2026). It consolidates the entire phishing attack lifecycle — domain registration and provisioning, realistic credential-harvesting page hosting, campaign delivery, real-time data exfiltration, and automated post-compromise actions — into a single web dashboard sold under a crypto-only, duration-based subscription with a reseller/affiliate (white-label) program.

The platform ships 87 ready-made phishing kits (Varonis observed 40+ at an earlier development stage) impersonating high-value brands across email/cloud (Google, Microsoft, Proton, Yahoo, Zoho, Apple iCloud/Apple ID, Dropbox, OneDrive, AWS), social media (Twitter/X, Meta/Facebook, Instagram, WhatsApp, TikTok, Discord, LinkedIn, Reddit, Telegram), developer infrastructure (GitHub, NPM, RubyGems, PyPI), authentication/SSO (LastPass, Okta, Citrix, Evernote), banking (PayPal, Wells Fargo, Bank of America, Fifth Third, BNC National, Atlantic Union, iQ Credit Union, Intuit/QuickBooks, TD Bank, EQ Bank, Orange France), brokerage (Robinhood, SoFi, Questrade, Trading 212), cryptocurrency exchanges (Binance, Coinbase, Coinspot, Bybit, MEXC, OKX, KuCoin, Crypto.com, Gate, Upbit, TradeZero), and hardware wallets (Ledger and Trezor firmware-update lures designed to harvest 24-word recovery seed phrases).

BlueKit's core advantage is adversary-in-the-middle (AiTM) session hijacking: it captures not only credentials but also cookies, local storage, and live session state, enabling MFA/2FA bypass via session-token replay through the integrated Octo Browser anti-detect browser. It additionally captures and stores WebAuthn credential material to undermine passwordless/passkey authentication. Automated post-compromise modules add the attacker as a Google Ads administrator, drive Google/Microsoft passkey enrollment, change passwords, and resolve Amazon 2FA — converting a single harvested login into durable, attacker-controlled account access.

The platform integrates CapSolver (CAPTCHA solving), NanoGPT and multiple LLMs (including an 'abliterated' safety-filter-removed Llama, plus GPT-4.1, Claude, Gemini, and DeepSeek as offered model options) for multilingual lure generation, and a peer-to-peer page-rendering architecture to obscure backend infrastructure. Operators receive real-time victim notifications via Telegram, with Jabber/XMPP, Session Protocol, and PGP for operator communications. Granular evasion controls include VPN/proxy blocking, headless/user-agent filtering, fingerprint-based filters, Cloudflare phishing-check and Safe Browsing bypass, cloaking, anti-bot filtering, selective crawler evasion, and per-site country bans (CIS-country targeting is explicitly prohibited per configuration). A leaked/exposed backend revealed five tables: Mammoths (victim credentials, FTS-indexed), Customers (operators, Argon2id password hashes), Sites_settings (per-site proxy/country/script configs), Webauthn_credentials, and Deposits (crypto payments with transaction hashes and HD-wallet derivation indices). As of the Varonis report no confirmed live campaign had been observed, but frequent active development indicates imminent operational deployment.

MITRE ATT&CK techniques used in TL-2026-0828

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1656 Impersonation; T1665 Hide Infrastructure

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1606 Forge Web Credentials

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1566 Phishing

Persistence

T1098 Account Manipulation; T1556 Modify Authentication Process

Collection

T1185 Browser Session Hijacking

Lateral Movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

  • Google — Gmail / Google Ads / Google Passkey
    Vulnerable versions: all (credential/session theft via impersonation)
  • Microsoft — Outlook / Live / Office 365
    Vulnerable versions: all (credential/session theft via impersonation)
  • Apple — iCloud / Apple ID
    Vulnerable versions: all (credential/session theft via impersonation)
  • Ledger — Hardware Wallet (firmware-update lure)
    Vulnerable versions: all (seed-phrase social engineering)
  • Trezor — Hardware Wallet (firmware-update lure)
    Vulnerable versions: all (seed-phrase social engineering)
  • Multiple — 87 impersonated brands (banking, crypto exchanges, brokerage, SSO, developer registries)
    Vulnerable versions: all (AiTM MFA bypass via session-cookie theft)

Remediation for BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

Immediate actions

  • Block BlueKit clearnet domains (bluekit.ws, bluekit.cc, bluekit.su, bluekit.pk) and the Tor onion service at perimeter and DNS resolvers
  • Hunt for AiTM session-cookie replay: flag sessions where authentication and subsequent API use originate from different IPs/ASNs/geographies or anti-detect browser fingerprints
  • Invalidate and rotate active sessions for any user who interacted with a suspected lure; force re-authentication
  • Alert on suspicious Google Ads administrator additions, passkey/WebAuthn enrollments, and password changes immediately following a login from a new location

Workarounds

  • Restrict crypto hardware-wallet firmware updates to vendor-native apps only; never enter seed phrases into any web page
  • Disable legacy/SMS MFA in favor of phishing-resistant factors
  • Geo/ASN-based step-up authentication for sensitive actions

Longer-term hardening

  • Deploy phishing-resistant FIDO2/WebAuthn hardware authenticators bound to origin (device-bound passkeys resist AiTM relay)
  • Enforce token binding / continuous access evaluation and short-lived sessions to limit cookie-replay value
  • Deploy conditional access requiring managed/compliant devices for high-value applications
  • Brand-impersonation monitoring and rapid takedown for the 87 targeted brands; user security-awareness training on AiTM and firmware-update seed-phrase lures

Weaknesses (CWE) in BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

CWE-1021, CWE-290, CWE-384, CWE-451, CWE-522

Timeline of BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

  • BleepingComputer reports on the new Bluekit phishing service, highlighting its AI assistant for multilingual lure generation and roughly 40 ready-made brand templates.
  • Varonis documents an exposed Bluekit backend revealing the operating model: a crypto-only, duration-based subscription with a white-label reseller program, Octo Browser anti-detect integration for session replay, CapSolver CAPTCHA solving, and automated post-compromise modules (Google Ads admin addition, passkey enrollment, password change, Amazon 2FA resolution).
  • Varonis Threat Labs publishes the first public analysis of the Bluekit all-in-one PhaaS platform, observing 40+ brand templates, an integrated AI assistant (abliterated Llama plus GPT-4.1/Claude/Gemini/DeepSeek options), and adversary-in-the-middle (AiTM) cookie/session capture; the platform is assessed as under active development with no confirmed live campaign yet.
  • Hackread, eBuilder Security, and Ciphers Security amplify the findings, emphasizing Bluekit's MFA-bypass session hijacking, WebAuthn/passkey targeting, and Telegram-based real-time credential exfiltration.
  • TechRadar reports that Bluekit can bypass enterprise 2FA protocols and emulate 40+ global brands through point-and-click campaign tooling, framing it as a low-skill barrier to scalable account takeover.
  • Threadlinqs Intelligence ingests BlueKit as an active PhaaS threat for IOC blocking and AiTM/session-replay detection engineering.
  • Clearnet domains, the Tor onion service, Cloudflare nameservers (fish/osmar.ns.cloudflare.com) and Web Analytics token, the internal platform identifier, and Luxhost (Dominican Republic) hosting attribution are disclosed for detection and blocking.
  • CloudSEK details the exposed five-table backend — Mammoths (FTS-indexed victim credentials), Customers (operators with Argon2id hashes), Sites_settings (per-site proxy/country/script configs with CIS-country bans), Webauthn_credentials, and Deposits (multi-coin crypto payments with HD-wallet derivation indices) — confirming platform maturity and affiliate compartmentalization.
  • CloudSEK TRIAD publishes a deep dark-web investigation documenting the matured platform: 87 phishing kits (up from the 40+ Varonis observed), clearnet (bluekit.ws/.cc/.su/.pk) and Tor infrastructure, Octo Browser/CapSolver/NanoGPT integration, WebAuthn capture, hardware-wallet (Ledger/Trezor) seed-phrase lures, a smishing module, HD-wallet crypto payments, and a reseller program.
  • Netcraft identifies BlueKit's shift to an rrweb-based Browser-in-the-Middle (BitM) technique — streaming a real, remotely-controlled attacker browser DOM to the victim over WebSocket so authentication completes on attacker infrastructure and yields a fully valid session — reported by BleepingComputer.

Update history for TL-2026-0828

Sources cited for BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

Threats related to BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling

Detection coverage for TL-2026-0828

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0828 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats