Executive Summary
Bluekit is a highly sophisticated Phishing-as-a-Service (PhaaS) platform that has evolved from traditional Adversary-in-the-Middle (AitM) proxying to a more resilient Browser-in-the-Middle (BitM) architecture. The platform democratizes advanced account takeover capabilities, providing over 80 templates targeting financial, cryptocurrency, and cloud services. By utilizing the 'rrweb' JavaScript library, Bluekit serializes and streams a live DOM from an attacker-controlled browser directly to the victim, ensuring high visual fidelity and rendering traditional multi-factor authentication (MFA) like SMS and app-based codes ineffective.
Technically, Bluekit integrates large language models (LLMs) for localized, error-free phishing content and voice cloning for social engineering. It employs a multi-layered evasion strategy, including WebRTC IP mismatch detection to identify researchers, randomized CSS filters to defeat pixel-hash detection, and decentralized peer-to-peer rendering. This shift to BitM allows the attacker to 'own' the authenticated session from the start within a consistent browser environment, significantly reducing the efficacy of fingerprinting-based security controls.
The business impact is severe, as it facilitates complete account takeover of privileged users without triggering traditional security alerts. Organizations must shift toward hardware-backed authentication (FIDO2) and continuous security validation to mitigate these automated, AI-driven threats.
