BlueKit is a commercial phishing-as-a-service platform used for large-scale credential theft, session hijacking, and account takeover. It is an operationally mature cybercriminal service that packages phishing infrastructure, centralized management, automated deployment, anti-detection controls, and campaign support into a subscription-based offering. BlueKit has been described as AI-assisted, with tooling for phishing email generation and a broad catalog of templates impersonating major email providers, cloud services, consumer platforms, financial institutions, developer services, e-commerce brands, and cryptocurrency services. BlueKit supports modern interactive phishing techniques beyond static credential-harvesting pages. It has been observed using browser-in-the-middle methods that relay a victim’s interaction with a legitimate login flow through attacker-controlled infrastructure, enabling theft of credentials, one-time codes, authentication tokens, session cookies, and subsequent authenticated access. Reporting also describes a migration toward peer-to-peer phishing page rendering intended to conceal backend infrastructure from browser developer tools and conventional network analysis, increasing resilience against detection, fingerprinting, and takedown. The platform includes extensive defense-evasion and victim-filtering features. Observed capabilities include browser fingerprinting, anti-bot checks, custom CAPTCHA gates, randomized visual manipulation to hinder screenshot-based detection, frequently changing obfuscated JavaScript, WebRTC-based proxy or VPN detection, phishing cloaking, and monitoring of reputation or phishing-detection systems. BlueKit also provides live victim monitoring and real-time operator notifications, allowing operators to observe sessions and react during active compromises. BlueKit’s ecosystem resembles a software-as-a-service operation, with subscription tiers, reseller support, dashboards, versioning, support channels, and integrations with third-party services for automation and anti-detect browsing. Some kits reportedly include post-compromise automation such as password changes, backup-code generation, passkey enrollment, and victim lockout, and support replay of stolen sessions for account takeover. Templates targeting cryptocurrency and hardware-wallet users have also been associated with theft of wallet recovery material, indicating a direct path to irreversible crypto theft. Available reporting suggests links to CIS-aligned cybercrime ecosystems based on operational characteristics and infrastructure choices, but the strongest high-confidence characterization is that BlueKit is a financially motivated cybercriminal phishing platform rather than a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AI-powered phishing kit/platform enabling automated infrastructure deployment, evasion, and AI-assisted phishing campaign creation, illustrating the rapid evolution of phishing operations.
Phishing-as-a-service operation that provides AI-assisted phishing email generation, branded credential-harvesting templates, and browser-in-the-middle capability to steal credentials and session tokens for account takeover.
Commercial phishing-as-a-service operation providing large-scale credential harvesting, adversary-in-the-middle phishing, session hijacking, account takeover, smishing, and automated post-compromise workflows against financial institutions, cloud providers, cryptocurrency platforms, e-commerce services, and enterprise accounts globally.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.