New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks
ID: eb0650c4-b86c-5272-a376-8a6dc539441f
STIX ID: report--eb0650c4-b86c-5272-a376-8a6dc539441f
Feed Name: HackRead
Varonis Threat Labs identified 'Bluekit', a phishing-as-a-service platform that supplies attackers with over 40 realistic site templates, domain management, and a dashboard to capture credentials, session cookies, and local storage. Bluekit uses an Adversary-in-the-Middle technique to steal session tokens and bypass MFA, streams live browser views to operators, exfiltrates captured data via Telegram, and includes an unsafe AI assistant to help build campaigns; researchers warn it is rapidly evolving with features like voice cloning and anti-bot cloaking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
