Bluekit Phishing Kit Streamlines Domains, 2FA Lures, and Session Hijacking
ID: 0f893d50-9ea1-5af4-ae21-840b7c1615a9
STIX ID: report--0f893d50-9ea1-5af4-ae21-840b7c1615a9
Feed Name: GBHackers
Bluekit is a newly discovered, actively developed phishing kit that centralizes the entire phishing lifecycle with 40+ prebuilt templates (Apple ID, Gmail, Outlook, GitHub, crypto services, etc.), automated domain purchase/registration, Telegram-based data exfiltration, anti-bot/anti-analysis protections, and optional add-ons (mail sender, voice cloning, AI assistant). Notably, it captures browser session data (cookies and local storage) enabling session hijacking and MFA bypass, offers live victim activity viewing, and exposes defenders to greater automation and ease-of-use in large-scale phishing campaigns; organizations should emphasize phishing-resistant MFA, session monitoring, and layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
