A newly discovered phishing kit called Bluekit is raising concerns in the cybersecurity community due to its advanced features, including an integrated AI assistant that helps attackers craft phishing campaigns.
What Is Bluekit?
Bluekit is a sophisticated phishing kit currently in active development that provides attackers with an extensive toolkit for creating convincing phishing pages. According to security firm Varonis, which gained access to Bluekit’s control panel, the kit offers over 40 website templates and a comprehensive dashboard for managing phishing operations.
Key Features
Bluekit stands out from other phishing kits due to its extensive feature set:
- AI Assistant: Built-in AI helper that generates structured campaign drafts with customizable placeholders
- Automated Domain Management: Operators can purchase or connect domains directly from the dashboard
- 40+ Templates: Pre-built templates for major services including Apple ID, GitHub, Gmail, Outlook, Ledger, ProtonMail, and cryptocurrency platforms
- Advanced Evasion: Antibot cloaking, geolocation emulation, and anti-analysis checks
- Session Tracking: Goes beyond credential harvesting by capturing cookies, local storage dumps, and providing live views of logged-in sessions
- Telegram Exfiltration: Uses Telegram as the default channel for sending captured data
- Voice Cloning & Spoofing: Includes voice cloning capabilities and various spoofing features
- 2FA Support: Handles two-factor authentication bypass attempts
How It Works
The Bluekit dashboard centralizes all phishing operations. Attackers can select a domain, choose a targeted brand, configure site behavior, and manage everything from login detection to redirect rules and proxy settings. Unlike traditional kits that require separate services for domain management and campaign tracking, Bluekit integrates everything into a single interface.
The AI Assistant panel exposes multiple model options and generates campaign drafts, though testing showed it produces structured templates with placeholders rather than ready-to-use content.
Current Status
As of now, Bluekit has not been observed in active phishing campaigns. Varonis notes that the kit appears to be in active development, with the developer releasing frequent feature and template updates. The rapid evolution of its feature set suggests that Bluekit could appear in future campaigns if adoption increases.
Why This Matters
Bluekit represents a concerning trend in cybercrime tooling: the democratization of sophisticated attacks through automation and AI assistance. By lowering the technical barrier and providing an all-in-one solution, kits like Bluekit enable less skilled attackers to launch convincing phishing campaigns.
The integration of AI assistance marks a new phase in phishing kit development, where automation helps attackers scale their operations and improve the quality of their social engineering attempts.
What to Watch For
Organizations should monitor for:
- Phishing emails targeting credentials for major cloud and cryptocurrency services
- Increased sophistication in phishing page design and behavior
- Campaigns leveraging Telegram for data exfiltration
- Attacks that attempt to bypass 2FA through session cookie theft
Security teams should ensure email filtering, user awareness training, and multi-factor authentication methods that resist session hijacking are in place.
Bluekit serves as a reminder that the phishing threat landscape continues to evolve, with AI-powered tools making attacks more accessible and potentially more effective.