Bluekit phishing platform adopts new technique for account theft

June 26, 2026  20:55

Researchers from Netcraft have discovered that the Bluekit phishing platform, operating under the phishing-as-a-service (PhaaS) model, has added support for browser-in-the-middle (BitM) attacks. This technology allows threat actors to intercept not only usernames and passwords but also active user sessions. Over the past week, specialists have also identified nearly 70 new domains linked to the Bluekit infrastructure, as reported by Bleeping Computer.

From email generation to session interception

Bluekit first drew the attention of experts in April 2026. At that time, Varonis researchers reported that the service was utilizing several AI models, including GPT-4.1, Claude, Gemini, DeepSeek, and Llama, to generate convincing phishing emails and was offering ready-made attack templates for Gmail, Outlook, iCloud, GitHub, Ledger, and other popular services.

Now, the platform has transitioned to a more sophisticated browser-in-the-middle attack scheme. In this scenario, the user interacts with the genuine login page, but through a browser controlled by the attacker. Upon successful authentication, the attacker obtains a valid session token and can gain access to the account without needing to re-enter the password.

How the new scheme works

To execute the attack, the platform uses rrweb, an open-source JavaScript library typically employed for recording user sessions and web analytics. In Bluekit, it allows the page content and user actions to be transmitted in real time via WebSocket.

Experts note that the library itself is not malicious; the danger lies in how it is being utilized.

Due to the continuous data transmission, slight delays may occur when typing text or clicking buttons. Such lags could be one of the few noticeable signs of an ongoing attack.

Protection against detection

Before stealing data, Bluekit verifies whether the visitor is an actual victim or a security researcher. To achieve this, it uses obfuscated JavaScript code, analyzes browser and device parameters, checks IP addresses via WebRTC, and deploys a CAPTCHA that mimics Cloudflare pages or the targeted service.

Furthermore, the platform operators can monitor the victim's actions almost in real time.

In brief

Bluekit continues to evolve rapidly, turning into one of the most technologically advanced phishing-as-a-service platforms. In addition to leveraging artificial intelligence for email generation, it now deploys browser-in-the-middle attacks to intercept active user sessions. Concurrently, the service is refining its stealth and anti-analysis mechanisms, making such attacks significantly harder to detect.

Follow NEWS.am Tech on Facebook and Twitter