Introduction to Bluekit Phishing Kit
The Bluekit phishing-as-a-service platform has continued to evolve, with nearly 70 new hostnames identified over the past week. This evolution includes the addition of browser-in-the-middle (BitM) capabilities, which enable improved data theft. First documented in April by Varonis researchers, Bluekit provides an AI assistant that supports multiple large language models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, for drafting phishing emails.
Browser-in-the-Middle (BitM) Capabilities
A new report from digital risk protection company Netcraft warns that Bluekit has switched from adversary-in-the-middle to a BitM mechanism. This mechanism uses the open-source JavaScript library 'rrweb' to serialize the page's DOM and stream it over a WebSocket connection to the victim. In a BitM attack, the victim interacts with a browser session controlled by the attacker, which loads the legitimate login page and relays requests and responses between the victim and the target service.
Netcraft notes that rrweb itself is a legitimate project widely used for session replay and analytics, and its presence in a web environment should not be interpreted as an indicator of compromise without a larger context. Images, fonts, and CSS are fetched through the phishing infrastructure, while the victim's inputs are forwarded back to the attacker's browser.
Attack Method and Indicators
The BitM attack method has been known since 2022, devised by researcher mr.d0x and later adopted for malicious activity. Before stealing the credentials, Bluekit uses a comprehensive victim qualification system to distinguish real targets from researchers or security crawlers. Anti-analysis systems in the latest Bluekit include randomized CSS filters, a large and frequently changing obfuscated JavaScript bundle, custom CAPTCHA, browser fingerprinting, and WebRTC-based IP mismatch detection.
Netcraft also reports that the live monitoring system Varonis previously documented is still available in BlueKit, allowing operators to monitor victims as they are entrapped in deceptive login sessions and track their actions after login. The researchers' report provides a set of indicators and signals associated with Bluekit, including CSS filter manipulation, an obfuscated JavaScript bundle, browser fingerprint checks, a WebSocket connection sending encrypted or binary data on login pages, and WebRTC IP mismatch detection on the landing page.
Defending Against Phishing Attacks
For organizations looking to defend against increasingly sophisticated phishing, business email compromise (BEC), and account takeover (ATO) attacks, it is essential to implement robust security measures. This includes using behavioral AI to detect and respond to modern phishing attacks, automating investigations and remediation, and reducing the operational burden caused by alert fatigue and increasingly sophisticated social engineering campaigns.
Security teams can also benefit from breach and attack simulation tests to ensure that their SIEM and EDR rules are effective in detecting threats. By testing every layer before attackers do, organizations can reduce the risk of successful attacks and improve their overall security posture.
- Test every layer before attackers do
- Security teams log 54% of successful attacks and alert on just 14%
- The rest move through your environment unseen
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about defending against phishing attacks.
Source: BleepingComputer