Bluekit Phishing Kit Automates Domain Setup and Session Hijacking

Historically, cybercriminals had to assemble phishing campaigns piece by piece. They would purchase a credential-harvesting page from one vendor, a domain rotator from another, and an SMS gateway from someone else.

Today, a newly discovered platform called Bluekit is changing this approach by offering a comprehensive, all-in-one phishing ecosystem.

Discovered by researchers at Varonis Threat Labs, Bluekit provides everything an attacker needs in a single package.

The platform advertises more than 40 website templates targeting major brands across email, cloud services, developer platforms, retail, and cryptocurrency. Supported templates include iCloud, Gmail, GitHub, ProtonMail, and Ledger.

Centralized Control and Session Hijacking

Bluekit streamlines the entire phishing workflow into one user-friendly operator dashboard. Instead of juggling multiple services, attackers can buy and configure domains directly within the same interface used to manage their malicious pages and stolen data.

The site-creation process is highly automated. Operators pick a domain, select a deployment mode, and choose their target template.

Some of the templates Bluekit supports. (Source: varonis)
Some of the templates Bluekit supports (Source: varonis)

Once a site is live, the kit offers granular control over its behavior. Attackers can configure redirect patterns, deploy anti-bot cloaking, spoof content, and set up device filters.

By default, the kit uses Telegram as its primary exfiltration channel to instantly alert operators of stolen data. Beyond basic credential harvesting, Bluekit excels at advanced session hijacking.

The Bluekit dashboard showing the main operator panel (Source: varonis)
The Bluekit dashboard showing the main operator panel (Source: varonis)

In a specialized “Mammoth Details” view, the platform tracks a victim’s session state and continuously dumps cookies and local browser storage.

It even provides the operator with a live look at what the victim sees after logging in.

The Site-creation flow with domain, mode, and template selection (Source: varonis)
The Site-creation flow with domain, mode, and template selection (Source: varonis)

AI Tools and Rapid Development

One of the most notable features inside Bluekit is its built-in AI Assistant. This tool comes with its own dedicated panel. It offers several high-profile language models, including GPT-4.1, Claude Sonnet 4, Gemini, and DeepSeek variants.

Because standard setups usually block malicious requests, researchers suspect these commercial models might rely on jailbroken or highly permissive instances.

During testing, Varonis researchers found that the default “abliterated Llama” model was the only one readily available without extra configuration.

When asked to generate a complex executive phishing lure targeting a CISO, the AI acted more like a structural guide than an expert copywriter.

It produced a solid campaign skeleton but heavily relied on generic placeholders and rough text that required manual cleanup before deployment.

Despite the AI’s current limitations, Bluekit remains a significant emerging threat. The developer maintains an aggressive update schedule, frequently adding new templates and features to the platform.

While it may still be in active development compared to more established phishing platforms, its rapid evolution and broad automation mean Bluekit is highly likely to fuel sophisticated cyberattacks in the near future.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories