BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target Financial-Sector CEOs via Browser-in-the-Middle
BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and (TL-2026-2315), also tracked as BlueKit, is a high-severity phishing campaign, first published 2026-09-03. It has no confirmed attribution, affects Multiple (financial-sector organizations) Executive (CEO) email, SSO, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-2315
- Threat ID
- TL-2026-2315
- Also known as
- BlueKit, Bluekit PhaaS
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-03
- Last reviewed
- 2026-09-03
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, cryptocurrency, cloud saas storage, government administration, news - media
- Target regions
- North America, Europe, india, East Asia
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and
Malware and tooling: BlueKit, ZeroBot, CapSolver, Level RMM, Octo Browser, ScreenConnect, Tactical RMM, rrweb
BlueKit, a subscription phishing-as-a-service (PhaaS) platform first documented in 2024, has added a ZeroBot bot-screening gate and legitimate-ScreenConnect delivery to a campaign specifically targeting CEOs at financial-industry firms with document-sharing lures. The platform uses browser-in-the-middle (BitM) session streaming (via the rrweb library over WebSocket) to capture credentials and post-MFA session tokens, then moves selected high-value victims into a fake document-viewer that installs a legitimate ConnectWise ScreenConnect client pointed at an attacker-controlled instance.
How BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and works
BlueKit (also styled Bluekit) is a commodity phishing-as-a-service kit that has been tracked by multiple independent research teams since April 2026, with roots reported back to April 2024. Its subscription model ($250/7 days, $480/14 days, $940/30 days, crypto-only payment) bundles 80-87 ready-made phishing templates spanning email/cloud providers (Gmail, Outlook, Yahoo, iCloud, ProtonMail), developer platforms (GitHub, Zoho), social media, banking, cryptocurrency exchanges, hardware wallets (Ledger, Trezor), and e-commerce brands, alongside automated domain registration, antibot/cloaking, and Telegram-based credential delivery.
On 2026-09-03, ZeroBEC (an Israeli threat-research startup) disclosed a variant of the platform used in an active campaign against CEOs of financial-sector companies. The chain begins with a document-sharing lure email. Before any phishing content is served, a bot-screening component the researchers named ZeroBot filters out automated scanners and security tooling, consistent with BlueKit's previously documented pre-engagement evasion phase (headless-browser fingerprinting, WebRTC IP-mismatch detection, custom CAPTCHA, randomized/obfuscated HTML and JavaScript). Victims who pass the screen are routed into a browser-in-the-middle flow: BlueKit's infrastructure opens the real target login page inside an attacker-controlled browser and streams the live DOM to the victim's browser using the open-source session-replay library rrweb over a WebSocket connection. The victim enters credentials and completes MFA against what appears to be the legitimate site, but the resulting authenticated session is created and retained on the attacker's machine, defeating standard MFA. For selected high-value victims, the operators then pivot out of the BitM flow into a fake document-viewer page that delivers a legitimate ConnectWise ScreenConnect client pre-configured to connect to an attacker-controlled ScreenConnect instance, giving the operators durable, tool-legitimate remote access to the victim's endpoint post-compromise.
This targeting and delivery pattern mirrors ZeroBEC's separately tracked Operation BlueDash (disclosed 2026-07-27), a Microsoft Teams/Zoom-themed "document too large to send" lure that used a fake Microsoft Store page (teamvem[.]com) to deliver an Inno Setup loader (supportdev.exe) enrolling victims into Level RMM, ScreenConnect, and Tactical RMM in parallel for redundant access; ZeroBEC assessed that operation to a Nigeria-based actor with moderate-to-high confidence based on infrastructure and GitHub evidence dating to February 2026. BlueKit itself shows CIS-aligned operational indicators (Jabber/XMPP preference, explicit CIS-country exclusion in its targeting logic) per CloudSEK's June 2026 analysis of an exposed BlueKit backend database, which recovered 29 database tables including a victim-credential store ("Mammoths"), WebAuthn credential captures, cryptocurrency payment/deposit records, and a reseller/distributor program with API-key access — evidence of a professional, SaaS-style crimeware operation rather than a single actor.
The same 2026-09-03 bulletin from The Hacker News also reported a separate, unrelated verified compromise: Dropbox disclosed that approximately 5,000 accounts were accessed without authorization between 2026-08-04 and 2026-08-21 because of a flaw in Lenovo's ID email-verification process. Attackers were able to register new Lenovo IDs using victims' email addresses and then use those Lenovo IDs to sign into Dropbox accounts linked via the legacy Lenovo ID integration, bypassing the victim's Dropbox password entirely on accounts that did not have Dropbox two-factor authentication enabled. Dropbox terminated all Lenovo-ID-authenticated sessions, severed the Lenovo ID/Dropbox account linkage, changed the login flow to require a Dropbox password even via Lenovo ID, and reported the incident to data-protection regulators.
MITRE ATT&CK techniques used in TL-2026-2315
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1684.001 Impersonation
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Discovery
T1082 System Information Discovery
Collection
T1185 Browser Session Hijacking
Execution
Initial Access
Resource Development
Affected products and versions in BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and
- Multiple (financial-sector organizations) — Executive (CEO) email, SSO, and cloud-collaboration accounts targeted via BlueKit BitM phishing
Vulnerable versions: N/A - social-engineering and session-theft technique, not a software vulnerability
Fixed in: N/A - ConnectWise — ScreenConnect (legitimate remote-access client abused as a post-compromise access tool)
Vulnerable versions: Any version, when installed via attacker-controlled instance/relay code delivered through the fake document-viewer
Fixed in: N/A - abuse of legitimate functionality, not a product vulnerability - Dropbox / Lenovo — Dropbox accounts linked via the legacy Lenovo ID single sign-on integration
Vulnerable versions: Accounts linked to a Lenovo ID without Dropbox two-factor authentication enabled, prior to the 2026-09 remediation
Fixed in: Lenovo ID/Dropbox account linkage terminated; Dropbox password now required even when signing in via Lenovo ID
Remediation for BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and
Immediate actions
- Block and monitor for the BlueKit storefront/admin domains (bluekit[.]ws, bluekit[.]cc, bluekit[.]su, bluekit[.]pk) and its Tor hidden service at perimeter and DNS resolvers
- Alert on outbound WebSocket connections carrying encrypted/binary session-replay traffic from browser sessions immediately following a document-sharing email lure
- Restrict installation of remote-access/RMM software (ScreenConnect, Level RMM, Tactical RMM) via application allowlisting; alert on any ScreenConnect install not sourced from the organization's sanctioned instance
- Force re-authentication and session revocation for financial-sector executive accounts (CEO/CFO/Treasury) that clicked a document-sharing link matching this campaign's pattern
- Enable Dropbox two-factor authentication on all accounts and audit for any residual Lenovo ID account linkages
Workarounds
- Instruct financial-sector executives to independently navigate to document-sharing services rather than following emailed links, and to verify any prompted software installs (especially ScreenConnect/RMM clients) out-of-band with IT before installing
Longer-term hardening
- Deploy phishing-resistant authentication (FIDO2/WebAuthn hardware security keys) for executive and finance-team accounts, since BitM defeats OTP/push-based MFA by hijacking the post-authentication session rather than the credential
- Implement browser isolation or managed-browser policies for high-value executive roles to prevent BitM session streaming from taking hold in an unmanaged browser context
- Establish a vendor/third-party identity-federation review process to catch weak email-verification logic in SSO/account-linking integrations (as exploited in the Lenovo ID/Dropbox case) before they are trusted for authentication
- Extend detection engineering to flag rrweb-library indicators, WebRTC IP-mismatch probing, and headless-browser fingerprinting scripts on inbound web traffic
Timeline of BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and
- BlueKit phishing kit is first documented by security researchers (approximate month; exact day not specified in public reporting).
- GitHub repository evidence tied to the actor infrastructure later linked to the related Operation BlueDash campaign dates back to this point, per ZeroBEC's infrastructure analysis.
- Varonis Threat Labs publishes the first detailed public analysis of BlueKit after obtaining internal dashboard access, documenting its AI assistant, 40+ phishing templates, and 2FA-support claims.
- CloudSEK TRIAD publishes an analysis of an exposed BlueKit backend database (29 tables), revealing 87 templates, the $250/$480/$940 subscription pricing tiers, and CIS-aligned operator infrastructure (Jabber/XMPP, CIS-country exclusion).
- Netcraft reports BlueKit has added browser-in-the-middle (BitM) capability using the rrweb library to stream live DOM sessions over WebSocket, and observes roughly 70 new phishing hostnames registered in a single week.
- ZeroBEC discloses Operation BlueDash, a related Teams/Zoom-themed 'document too large' lure campaign delivering ScreenConnect, Level RMM, and Tactical RMM via a fake Microsoft Store loader (supportdev.exe) hosted at teamvem[.]com, attributed with moderate-to-high confidence to a Nigeria-based actor.
- Unauthorized access begins to Dropbox accounts linked via the legacy Lenovo ID integration, exploiting a flaw in Lenovo's email-verification process.
- The unauthorized-access window for the Lenovo ID-linked Dropbox account compromise closes; Dropbox begins remediation.
- Dropbox publicly discloses that approximately 5,000 accounts were compromised via the Lenovo ID integration, terminates all Lenovo-ID-authenticated sessions, severs the account linkage, and reports the incident to data-protection regulators.
- ZeroBEC and The Hacker News report the BlueKit variant that adds ZeroBot bot-screening and legitimate-ScreenConnect delivery, specifically targeting financial-sector CEOs via document-sharing lures, published in the same bulletin as the Dropbox/Lenovo disclosure.
Sources cited for BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and
- ThreatsDay Bulletin: CEO Phishing Kits, 5K Dropbox Accounts Hacked, and More
- BlueKit PhaaS: Browser-in-the-Middle and ScreenConnect Delivery Targets Financial-Sector CEOs
- Bluekit Phishing-as-a-Service: Browser-in-the-Middle (BitM) Analysis
- Bluekit phishing kit adopts browser-in-the-middle for login theft
- Bluekit Phishing as a Service (PhaaS)
- Meet Bluekit: The AI-Powered All-in-One Phishing Kit
- Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking
- Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
- Operation BlueDash: Multi-RMM Workplace Phishing
- Dropbox says about 5,000 accounts compromised in August hack
- Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
More in phishing
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
- Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach
Detection coverage for TL-2026-2315
As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2315 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.