Threats

Bluekit Phishing Kit Evolves with Browser-in-the-Middle Capabilities

June 26, 2026 00:10 · 12 min read
Bluekit Phishing Kit Evolves with Browser-in-the-Middle Capabilities

Introduction to Bluekit Phishing Kit

The Bluekit phishing-as-a-service platform has continued to evolve, with nearly 70 new hostnames identified over the past week. This evolution includes the addition of browser-in-the-middle (BitM) capabilities, which enable improved data theft. First documented in April by Varonis researchers, Bluekit provides an AI assistant that supports multiple large language models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, for drafting phishing emails.

Browser-in-the-Middle (BitM) Capabilities

A new report from digital risk protection company Netcraft warns that Bluekit has switched from adversary-in-the-middle to a BitM mechanism. This mechanism uses the open-source JavaScript library 'rrweb' to serialize the page's DOM and stream it over a WebSocket connection to the victim. In a BitM attack, the victim interacts with a browser session controlled by the attacker, which loads the legitimate login page and relays requests and responses between the victim and the target service.

Netcraft notes that rrweb itself is a legitimate project widely used for session replay and analytics, and its presence in a web environment should not be interpreted as an indicator of compromise without a larger context. Images, fonts, and CSS are fetched through the phishing infrastructure, while the victim's inputs are forwarded back to the attacker's browser.

Attack Method and Indicators

The BitM attack method has been known since 2022, devised by researcher mr.d0x and later adopted for malicious activity. Before stealing the credentials, Bluekit uses a comprehensive victim qualification system to distinguish real targets from researchers or security crawlers. Anti-analysis systems in the latest Bluekit include randomized CSS filters, a large and frequently changing obfuscated JavaScript bundle, custom CAPTCHA, browser fingerprinting, and WebRTC-based IP mismatch detection.

Netcraft also reports that the live monitoring system Varonis previously documented is still available in BlueKit, allowing operators to monitor victims as they are entrapped in deceptive login sessions and track their actions after login. The researchers' report provides a set of indicators and signals associated with Bluekit, including CSS filter manipulation, an obfuscated JavaScript bundle, browser fingerprint checks, a WebSocket connection sending encrypted or binary data on login pages, and WebRTC IP mismatch detection on the landing page.

Defending Against Phishing Attacks

For organizations looking to defend against increasingly sophisticated phishing, business email compromise (BEC), and account takeover (ATO) attacks, it is essential to implement robust security measures. This includes using behavioral AI to detect and respond to modern phishing attacks, automating investigations and remediation, and reducing the operational burden caused by alert fatigue and increasingly sophisticated social engineering campaigns.

Security teams can also benefit from breach and attack simulation tests to ensure that their SIEM and EDR rules are effective in detecting threats. By testing every layer before attackers do, organizations can reduce the risk of successful attacks and improve their overall security posture.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about defending against phishing attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free