BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target Financial-Sector CEOs via Browser-in-the-Middle

BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and (TL-2026-2315), also tracked as BlueKit, is a high-severity phishing campaign, first published 2026-09-03. It has no confirmed attribution, affects Multiple (financial-sector organizations) Executive (CEO) email, SSO, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-2315

Threat ID
TL-2026-2315
Also known as
BlueKit, Bluekit PhaaS
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-03
Last reviewed
2026-09-03
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, banking, cryptocurrency, cloud saas storage, government administration, news - media
Target regions
North America, Europe, india, East Asia
Detection rules
9
Indicators of compromise
25

Malware and tooling in BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and

Malware and tooling: BlueKit, ZeroBot, CapSolver, Level RMM, Octo Browser, ScreenConnect, Tactical RMM, rrweb

BlueKit, a subscription phishing-as-a-service (PhaaS) platform first documented in 2024, has added a ZeroBot bot-screening gate and legitimate-ScreenConnect delivery to a campaign specifically targeting CEOs at financial-industry firms with document-sharing lures. The platform uses browser-in-the-middle (BitM) session streaming (via the rrweb library over WebSocket) to capture credentials and post-MFA session tokens, then moves selected high-value victims into a fake document-viewer that installs a legitimate ConnectWise ScreenConnect client pointed at an attacker-controlled instance.

How BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and works

BlueKit (also styled Bluekit) is a commodity phishing-as-a-service kit that has been tracked by multiple independent research teams since April 2026, with roots reported back to April 2024. Its subscription model ($250/7 days, $480/14 days, $940/30 days, crypto-only payment) bundles 80-87 ready-made phishing templates spanning email/cloud providers (Gmail, Outlook, Yahoo, iCloud, ProtonMail), developer platforms (GitHub, Zoho), social media, banking, cryptocurrency exchanges, hardware wallets (Ledger, Trezor), and e-commerce brands, alongside automated domain registration, antibot/cloaking, and Telegram-based credential delivery.

On 2026-09-03, ZeroBEC (an Israeli threat-research startup) disclosed a variant of the platform used in an active campaign against CEOs of financial-sector companies. The chain begins with a document-sharing lure email. Before any phishing content is served, a bot-screening component the researchers named ZeroBot filters out automated scanners and security tooling, consistent with BlueKit's previously documented pre-engagement evasion phase (headless-browser fingerprinting, WebRTC IP-mismatch detection, custom CAPTCHA, randomized/obfuscated HTML and JavaScript). Victims who pass the screen are routed into a browser-in-the-middle flow: BlueKit's infrastructure opens the real target login page inside an attacker-controlled browser and streams the live DOM to the victim's browser using the open-source session-replay library rrweb over a WebSocket connection. The victim enters credentials and completes MFA against what appears to be the legitimate site, but the resulting authenticated session is created and retained on the attacker's machine, defeating standard MFA. For selected high-value victims, the operators then pivot out of the BitM flow into a fake document-viewer page that delivers a legitimate ConnectWise ScreenConnect client pre-configured to connect to an attacker-controlled ScreenConnect instance, giving the operators durable, tool-legitimate remote access to the victim's endpoint post-compromise.

This targeting and delivery pattern mirrors ZeroBEC's separately tracked Operation BlueDash (disclosed 2026-07-27), a Microsoft Teams/Zoom-themed "document too large to send" lure that used a fake Microsoft Store page (teamvem[.]com) to deliver an Inno Setup loader (supportdev.exe) enrolling victims into Level RMM, ScreenConnect, and Tactical RMM in parallel for redundant access; ZeroBEC assessed that operation to a Nigeria-based actor with moderate-to-high confidence based on infrastructure and GitHub evidence dating to February 2026. BlueKit itself shows CIS-aligned operational indicators (Jabber/XMPP preference, explicit CIS-country exclusion in its targeting logic) per CloudSEK's June 2026 analysis of an exposed BlueKit backend database, which recovered 29 database tables including a victim-credential store ("Mammoths"), WebAuthn credential captures, cryptocurrency payment/deposit records, and a reseller/distributor program with API-key access — evidence of a professional, SaaS-style crimeware operation rather than a single actor.

The same 2026-09-03 bulletin from The Hacker News also reported a separate, unrelated verified compromise: Dropbox disclosed that approximately 5,000 accounts were accessed without authorization between 2026-08-04 and 2026-08-21 because of a flaw in Lenovo's ID email-verification process. Attackers were able to register new Lenovo IDs using victims' email addresses and then use those Lenovo IDs to sign into Dropbox accounts linked via the legacy Lenovo ID integration, bypassing the victim's Dropbox password entirely on accounts that did not have Dropbox two-factor authentication enabled. Dropbox terminated all Lenovo-ID-authenticated sessions, severed the Lenovo ID/Dropbox account linkage, changed the login flow to require a Dropbox password even via Lenovo ID, and reported the incident to data-protection regulators.

MITRE ATT&CK techniques used in TL-2026-2315

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion; T1684.001 Impersonation

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Discovery

T1082 System Information Discovery

Collection

T1185 Browser Session Hijacking

Execution

T1204 User Execution

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure

Affected products and versions in BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and

  • Multiple (financial-sector organizations) — Executive (CEO) email, SSO, and cloud-collaboration accounts targeted via BlueKit BitM phishing
    Vulnerable versions: N/A - social-engineering and session-theft technique, not a software vulnerability
    Fixed in: N/A
  • ConnectWise — ScreenConnect (legitimate remote-access client abused as a post-compromise access tool)
    Vulnerable versions: Any version, when installed via attacker-controlled instance/relay code delivered through the fake document-viewer
    Fixed in: N/A - abuse of legitimate functionality, not a product vulnerability
  • Dropbox / Lenovo — Dropbox accounts linked via the legacy Lenovo ID single sign-on integration
    Vulnerable versions: Accounts linked to a Lenovo ID without Dropbox two-factor authentication enabled, prior to the 2026-09 remediation
    Fixed in: Lenovo ID/Dropbox account linkage terminated; Dropbox password now required even when signing in via Lenovo ID

Remediation for BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and

Immediate actions

  • Block and monitor for the BlueKit storefront/admin domains (bluekit[.]ws, bluekit[.]cc, bluekit[.]su, bluekit[.]pk) and its Tor hidden service at perimeter and DNS resolvers
  • Alert on outbound WebSocket connections carrying encrypted/binary session-replay traffic from browser sessions immediately following a document-sharing email lure
  • Restrict installation of remote-access/RMM software (ScreenConnect, Level RMM, Tactical RMM) via application allowlisting; alert on any ScreenConnect install not sourced from the organization's sanctioned instance
  • Force re-authentication and session revocation for financial-sector executive accounts (CEO/CFO/Treasury) that clicked a document-sharing link matching this campaign's pattern
  • Enable Dropbox two-factor authentication on all accounts and audit for any residual Lenovo ID account linkages

Workarounds

  • Instruct financial-sector executives to independently navigate to document-sharing services rather than following emailed links, and to verify any prompted software installs (especially ScreenConnect/RMM clients) out-of-band with IT before installing

Longer-term hardening

  • Deploy phishing-resistant authentication (FIDO2/WebAuthn hardware security keys) for executive and finance-team accounts, since BitM defeats OTP/push-based MFA by hijacking the post-authentication session rather than the credential
  • Implement browser isolation or managed-browser policies for high-value executive roles to prevent BitM session streaming from taking hold in an unmanaged browser context
  • Establish a vendor/third-party identity-federation review process to catch weak email-verification logic in SSO/account-linking integrations (as exploited in the Lenovo ID/Dropbox case) before they are trusted for authentication
  • Extend detection engineering to flag rrweb-library indicators, WebRTC IP-mismatch probing, and headless-browser fingerprinting scripts on inbound web traffic

Timeline of BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and

  • BlueKit phishing kit is first documented by security researchers (approximate month; exact day not specified in public reporting).
  • GitHub repository evidence tied to the actor infrastructure later linked to the related Operation BlueDash campaign dates back to this point, per ZeroBEC's infrastructure analysis.
  • Varonis Threat Labs publishes the first detailed public analysis of BlueKit after obtaining internal dashboard access, documenting its AI assistant, 40+ phishing templates, and 2FA-support claims.
  • CloudSEK TRIAD publishes an analysis of an exposed BlueKit backend database (29 tables), revealing 87 templates, the $250/$480/$940 subscription pricing tiers, and CIS-aligned operator infrastructure (Jabber/XMPP, CIS-country exclusion).
  • Netcraft reports BlueKit has added browser-in-the-middle (BitM) capability using the rrweb library to stream live DOM sessions over WebSocket, and observes roughly 70 new phishing hostnames registered in a single week.
  • ZeroBEC discloses Operation BlueDash, a related Teams/Zoom-themed 'document too large' lure campaign delivering ScreenConnect, Level RMM, and Tactical RMM via a fake Microsoft Store loader (supportdev.exe) hosted at teamvem[.]com, attributed with moderate-to-high confidence to a Nigeria-based actor.
  • Unauthorized access begins to Dropbox accounts linked via the legacy Lenovo ID integration, exploiting a flaw in Lenovo's email-verification process.
  • The unauthorized-access window for the Lenovo ID-linked Dropbox account compromise closes; Dropbox begins remediation.
  • Dropbox publicly discloses that approximately 5,000 accounts were compromised via the Lenovo ID integration, terminates all Lenovo-ID-authenticated sessions, severs the account linkage, and reports the incident to data-protection regulators.
  • ZeroBEC and The Hacker News report the BlueKit variant that adds ZeroBot bot-screening and legitimate-ScreenConnect delivery, specifically targeting financial-sector CEOs via document-sharing lures, published in the same bulletin as the Dropbox/Lenovo disclosure.

Sources cited for BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and

More in phishing

Detection coverage for TL-2026-2315

As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2315 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats