Bluekit Phishing-as-a-Service Browser-in-the-Middle Attack Analysis
Score: 8/10

Bluekit Phishing-as-a-Service Browser-in-the-Middle Attack Analysis

Bluekit PhaaS leverages advanced Browser-in-the-Middle (BitM) techniques and AI to bypass MFA by streaming live DOM interactions to victims.

Executive Summary

Bluekit is a highly sophisticated Phishing-as-a-Service (PhaaS) platform that has evolved from traditional Adversary-in-the-Middle (AitM) proxying to a more resilient Browser-in-the-Middle (BitM) architecture. The platform democratizes advanced account takeover capabilities, providing over 80 templates targeting financial, cryptocurrency, and cloud services. By utilizing the 'rrweb' JavaScript library, Bluekit serializes and streams a live DOM from an attacker-controlled browser directly to the victim, ensuring high visual fidelity and rendering traditional multi-factor authentication (MFA) like SMS and app-based codes ineffective.

Technically, Bluekit integrates large language models (LLMs) for localized, error-free phishing content and voice cloning for social engineering. It employs a multi-layered evasion strategy, including WebRTC IP mismatch detection to identify researchers, randomized CSS filters to defeat pixel-hash detection, and decentralized peer-to-peer rendering. This shift to BitM allows the attacker to 'own' the authenticated session from the start within a consistent browser environment, significantly reducing the efficacy of fingerprinting-based security controls.

The business impact is severe, as it facilitates complete account takeover of privileged users without triggering traditional security alerts. Organizations must shift toward hardware-backed authentication (FIDO2) and continuous security validation to mitigate these automated, AI-driven threats.

Key Details

Threat Name

Bluekit PhaaS

Affects

—

Adversary

cl0p Other Adversaries and Aliases: Bluekit

Malware/Tools

Bluekit PhaaS, Bluekit, Evilginx

Report Score

8out of 10
Quality Score
Good
IOC Quality6
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources