Historically, cybercriminals had to assemble phishing campaigns piece by piece. They would purchase a credential-harvesting page from one vendor, a domain rotator from another, and an SMS gateway from someone else.
Today, a newly discovered platform called Bluekit is changing this approach by offering a comprehensive, all-in-one phishing ecosystem.
Discovered by researchers at Varonis Threat Labs, Bluekit provides everything an attacker needs in a single package.
The platform advertises more than 40 website templates targeting major brands across email, cloud services, developer platforms, retail, and cryptocurrency. Supported templates include iCloud, Gmail, GitHub, ProtonMail, and Ledger.
Centralized Control and Session Hijacking
Bluekit streamlines the entire phishing workflow into one user-friendly operator dashboard. Instead of juggling multiple services, attackers can buy and configure domains directly within the same interface used to manage their malicious pages and stolen data.
The site-creation process is highly automated. Operators pick a domain, select a deployment mode, and choose their target template.

Once a site is live, the kit offers granular control over its behavior. Attackers can configure redirect patterns, deploy anti-bot cloaking, spoof content, and set up device filters.
By default, the kit uses Telegram as its primary exfiltration channel to instantly alert operators of stolen data. Beyond basic credential harvesting, Bluekit excels at advanced session hijacking.

In a specialized “Mammoth Details” view, the platform tracks a victim’s session state and continuously dumps cookies and local browser storage.
It even provides the operator with a live look at what the victim sees after logging in.

AI Tools and Rapid Development
One of the most notable features inside Bluekit is its built-in AI Assistant. This tool comes with its own dedicated panel. It offers several high-profile language models, including GPT-4.1, Claude Sonnet 4, Gemini, and DeepSeek variants.
Because standard setups usually block malicious requests, researchers suspect these commercial models might rely on jailbroken or highly permissive instances.
During testing, Varonis researchers found that the default “abliterated Llama” model was the only one readily available without extra configuration.
When asked to generate a complex executive phishing lure targeting a CISO, the AI acted more like a structural guide than an expert copywriter.
It produced a solid campaign skeleton but heavily relied on generic placeholders and rough text that required manual cleanup before deployment.
Despite the AI’s current limitations, Bluekit remains a significant emerging threat. The developer maintains an aggressive update schedule, frequently adding new templates and features to the platform.
While it may still be in active development compared to more established phishing platforms, its rapid evolution and broad automation mean Bluekit is highly likely to fuel sophisticated cyberattacks in the near future.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.