MalwareBytes

AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes


In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam.

The discovery highlights an important feature of the cybercrime economy: criminals don’t necessarily need to build their own infrastructure from scratch. Instead, they can buy ready-made services that handle much of the complicated work for them.

The same pattern is well established in phishing. Scam emails are no longer limited to poorly written, easily spotted phishing attempts. Cybercriminals now use complete, subscription-based platforms that make launching convincing attacks as easy as signing up for a monthly service.

One of the most dangerous examples of this trend is BlueKit, a phishing-as-a-service (PhaaS) toolkit designed to automate and scale account hijacking.

BlueKit allows attackers to manage entire phishing campaigns through a single dashboard without needing deep technical knowledge.

 BlueKit thread on underground cybercrime forum
“petrushka” (Russian for parsley), the operator behind BlueKit
“petrushka” (Russian for parsley), the operator behind BlueKit

BlueKit’s origins

The Malwarebytes research team has been tracking BlueKit’s development since the service first appeared on a prominent cybercrime forum in April.

Rather than simply documenting its initial capabilities, our researchers followed its evolution over time, watching how the service developed and what its growing capabilities could mean for cybercriminal operations.

The offer of “BlueKit” by the threat actor “petrushka”
BlueKit offered by the threat actor “petrushka”

A template library targeting familiar brands 

As of September, BlueKit boasts an extensive template library supporting 97 distinct brands across 176 variants. The service’s operators describe these phishing pages as: 

“pixel-perfect and ready to deploy in one click.”

The offer of “BlueKit” (extended)
The offer of “BlueKit” (extended)
BlueKit’s website
BlueKit’s website
Phishing kits list on BlueKit’s website
Phishing kits list on BlueKit’s website

Our analysis shows that the platform targets both consumer and business platforms. Its phishing kit templates include:

  • Consumer services: Templates impersonating major providers, including Amazon, Booking.com, Google/Gmail, and Apple.
  • Finance and cryptocurrency: Templates impersonating financial institutions such as American Express and Bank of America, alongside numerous cryptocurrency exchanges.
  • Social media and communications: Templates impersonating major social media platforms including TikTok, Facebook, and X.
  • Generative AI platforms: Templates designed to steal login details for services including OpenAI and Anthropic.

Below is a video demo of a phishing page impersonating the crypto wallet provider Trezor:

Beyond consumer-oriented attacks, BlueKit also presents an acute threat to businesses by providing the tools necessary to target corporate logins. 

Our team found support for critical business infrastructure and single sign-on (SSO) gateways. This includes customer relationship and marketing automation platforms, such as Salesforce and HubSpot, developer and source control environments like GitHub, and security services including Check Point, Citrix, Cloudflare, and Cisco.

Business-oriented phishing templates on BlueKit’s website
Business-oriented phishing templates on BlueKit’s website

One of the interesting things about BlueKit is that its creators are constantly adding new features, much like a legitimate software company releasing updates for its apps.

For example, on July 26, the BlueKit team used its official Telegram channel to announce an upcoming upgrade: a built-in SMS sender. Less than a month later, on August 10, they announced its release.

The new tool allows scammers to send text messages directly from the BlueKit dashboard. Alongside phishing emails, attackers can now easily send scam texts (called “smishing”) to trick people into clicking malicious links.

The operators say the update even lets attackers use local US phone numbers, which could make the messages appear more trustworthy. It gives them an entirely new, highly effective way to deliver scams from one control panel.

SMS sender announcement in BlueKit’s Telegram channel
SMS sender announcement in BlueKit’s Telegram channel
SMS sender module on BlueKit’s website
SMS sender module on BlueKit’s website

But BlueKit’s creators aren’t just focused on adding shiny new tools like the SMS sender. They’re also constantly working behind the scenes to improve their core product. A September update, for example, improved their fake website templates to make them look even more convincing, and upgraded the hidden technology they use to steal and manage sessions.

BlueKit’s September updates
BlueKit’s September updates

Three ways BlueKit makes phishing easier for scammers

After monitoring BlueKit’s development and analyzing its capabilities, our research team identified three ways the service lowers the barrier to launching sophisticated phishing attacks: setting up a site, capturing account access, and using AI to support the attack.

1. Quick setup

BlueKit is an “easy-to-install” phishing service, highlighting just how quickly sophisticated phishing infrastructure can be deployed. 

According to its operators, an attacker can connect a domain and have a phishing site ready in around 10 minutes. The cheapest subscription costs $250 for seven days, and an attacker could potentially go from purchasing the service to launching a sophisticated phishing campaign in a matter of minutes.

Description of BlueKit’s easy setup procedure
Description of BlueKit’s easy setup procedure

2. More than password theft

When most people think of phishing, they picture a scammer tricking them into handing over a username and password. But BlueKit goes much deeper than a basic smash-and-grab.

Behind the scenes, this tool secretly collects a complete digital profile of your computer , including a device fingerprint, cookie sessions, and even passkeys. 

Device fingerprint: BlueKit records your IP address, web browser details, and device characteristics. Together, details such as screen size, operating system, and hidden hardware settings can form a “fingerprint” that helps distinguish one browser or device from another.

Many modern security systems look for familiar devices to double-check that it’s really you trying to log in. So by stealing this background information alongside your password, an attacker can mimic your device to bypass security checks.

Session cookies: When you log into a website like your email or online bank, the site doesn’t make you retype your password every time you open a new page. Instead, it places a tiny file on your device called a session cookie to recognize that you’ve already signed in.

Think of a session cookie like a VIP wristband given to you at a concert entrance. Once the guard checks your ticket—your login—they give you a wristband. While you’re wearing that wristband, you can walk freely in and out of the venue without showing your ticket again.

Instead of just stealing your ticket, BlueKit also steals the wristband itself. Once the attacker takes your session cookie, they can paste it into their own browser and walk straight into your active account. They don’t need to guess your password, and they don’t need to ask for a two-factor code. The website already thinks they are you.

Description of BlueKit’s data-capturing capabilitie
Description of BlueKit’s data-capturing capabilities
Live demos with real credentials by the BlueKit team
Live demos using real credentials, shared by the BlueKit team

3. A built-in AI assistant

What makes BlueKit especially interesting right now is that it comes with its own built-in, “no-rules” artificial intelligence.

Think of it like a malicious version of ChatGPT, built directly into the scammer’s toolkit. Usually, AI tools have safety filters to prevent people from doing illegal things. BlueKit’s creators, however, have removed those guardrails, advertising that their custom AI will answer “even extreme prompts” and help with “fraud-related questions.”

Instead of writing convincing scam emails from scratch, an attacker can simply ask the AI to write phishing emails and fake text messages.

This is a huge development. BlueKit illustrates how advanced AI features are not just for legitimate businesses. They are being packaged and sold as standard features in cybercriminal services, making it easier for attackers to launch highly convincing attacks.

BlueKit’s advertised AI capabilities
BlueKit’s advertised AI capabilities

The business behind BlueKit

BlueKit’s claimed customer numbers also point to a potentially significant revenue stream. On August 29, the operators announced that the service had passed 1,000 customers.

Based on the advertised subscription prices, we can illustrate the potential revenue generated so far, although the actual distribution of subscriptions is unknown.

BlueKit’s announcement claiming more than 1,000 customers
BlueKit’s announcement claiming more than 1,000 customers
  • If all 1,000 customers purchased one 7-day subscription at $250: $250,000 in gross revenue.
  • If all 1,000 customers purchased one 30-day subscription at $940: $940,000 in gross revenue.
  • If purchases were split roughly equally between the 7-day ($250), 14-day ($480), and 30-day ($940) plans: Approximately $557,000 in gross revenue.

These are hypothetical calculations, but even so, the figures are a striking example of the economics behind phishing-as-a-service: operators can potentially generate hundreds of thousands of dollars in revenue by selling access to their infrastructure to other criminals. 

BlueKit’s advertised subscription prices
BlueKit’s advertised subscription prices

What this means for you

Phishing has officially evolved beyond obvious scam pages filled with typos and blurry logos. BlueKit combines convincing login pages, a built-in AI assistant, and subscription access to tools that once required more technical skills. 

Services like these make sophisticated phishing easier to launch, allowing scammers to generate a highly convincing, customized phishing attack from scratch in as little as 10 minutes.

Ultimately, services like BlueKit mean that advanced, highly deceptive cyberattacks are no longer limited to elite hackers. They are now fast, cheap, and accessible to anyone with a few dollars to spare.

Polished wording and familiar branding are not proof that a message or login page is genuine. 

  • Open the app or website yourself. If a message asks you to sign in, use the official app or a saved bookmark rather than the link in the email or message.
  • Check the website address before signing in. Scammers can use lookalike addresses with small spelling changes, known as typosquatting. A password manager can help as it will only autofill logins on the correct site, while Malwarebytes Browser Guard can help block phishing pages. 
  • Use passkeys where available, and keep two-factor authentication enabled. These are still valuable protections, although some phishing techniques can capture sessions after a user completes a login. 
  • If you signed in through a suspicious link, secure your account through the official app or website. Change your password, review your account activity, and sign out of all sessions.

Pro tip: Malwarebytes Scam Guard can also help you assess a suspicious message before you act on it.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →




Source link