Scams
AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a
Malwarebytes Labs··10 min read
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam. The discovery highlights an important feature of the cybercrime economy: criminals don’t necessarily need to build their own infrastructure from scratch. Instead, they can buy ready-made services that handle much of the complicated work for them. The same pattern is well established in phishing . Scam emails are no longer limited to poorly written, easily spotted phishing attempts. Cybercriminals now use complete, subscription-based platforms that make launching convincing attacks as easy as signing up for a monthly service. One of the most dangerous examples of this trend is BlueKit , a phishing-as-a-service (PhaaS) toolkit designed to automate and scale account hijacking. BlueKit allows attackers to manage entire phishing campaigns through a single dashboard without needing deep technical knowledge. BlueKit thread on underground cybercrime forum “petrushka” (Russian for parsley), the operator behind BlueKit BlueKit’s origin s The Malwarebytes research team has been tracking BlueKit’s development since the service first appeared on a prominent cybercrime forum in April. Rather than simply documenting its initial capabilities, our researchers followed its evolution over time, watching how the service developed and what its growing capabilities could mean for cybercriminal operations. BlueKit offered by the threat actor “petrushka” A template library targeting familiar brands As of September, BlueKit boasts an extensive template library supporting 97 distinct brands across 176 variants . The service’s operators describe these phishing pages as: “pixel-perfect and ready to deploy in one click.” The offer of “BlueKit” (extended) BlueKit’s website Phishing kits list on BlueKit’s website Our analysis shows that the platform targets both consumer and business platforms . Its phishing kit templates include: Consumer services: Templates impersonating major providers, including Amazon, Booking.com, Google/Gmail, and Apple. Finance and cryptocurrency: Templates impersonating financial institutions such as American Express and Bank of America, alongside numerous cryptocurrency exchanges. Social media and communications: Templates impersonating major social media platforms including TikTok, Facebook, and X. Generative AI platforms: Templates designed to steal login details for services including OpenAI and Anthropic. Below is a video demo of a phishing page impersonating the crypto wallet provider Trezor: Beyond consumer-oriented attacks, BlueKit also presents an acute threat to businesses by providing the tools necessary to target corporate logins. Our team found support for critical business infrastructure and single sign-on (SSO) gateways. This includes customer relationship and marketing automation platforms, such as Salesforce and HubSpot, developer and source control environments like GitHub, and security services including Check Point, Citrix, Cloudflare, and Cisco. Business-oriented phishing templates on BlueKit’s website A toolkit that never stops updating One of the interesting things about BlueKit is that its creators are constantly adding new features, much like a legitimate software company releasing updates for its apps. For example, on July 26, the BlueKit team used its official Telegram channel to announce an upcoming upgrade: a built-in SMS sender. Less than a month later, on August 10, they announced its release. The new tool allows scammers to send text messages directly from the BlueKit dashboard. Alongside phishing emails, attackers can now easily send scam texts (called “smishing”) to trick people into clicking malicious links. The operators say the update even lets attackers use local US phone numbers, which could make the messages appear more trustworthy. It gives them an entirely new, highly effective way to deliver scams from one control panel. SMS sender announcement in BlueKit’s Telegram channel SMS sender module on BlueKit’s website But BlueKit’s creators aren’t just focused on adding shiny new tools like the SMS sender. They’re also constantly working behind the scenes to improve their core product. A September update, for example, improved their fake website templates to make them look even more convincing, and upgraded the hidden technology they use to steal and manage sessions. BlueKit’s September updates Three ways BlueKit makes phishing easier for scammers After monitoring BlueKit’s development and analyzing its capabilities, our research team identified three ways the service lowers the barrier to launching sophisticated phishing attacks: setting up a site, capturing account access, and using AI to support the attack. 1. Quick setup BlueKit is an “easy-to-install” phishing service, highlighting just how quickly sophisticated phishing infrastructure can be deployed. According to its operators, an attacker can connect a domain and have a phishing site ready in around 10 minutes. The cheapest subscription costs $250 for seven days, and an attacker could potentially go from purchasing the service to launching a sophisticated phishing campaign in a matter of minutes. Description of BlueKit’s easy setup procedure 2. More than password theft When most people think of phishing, they picture a scammer tricking them into handing over a username and password. But BlueKit goes much deeper than a basic smash-and-grab. Behind the scenes, this tool secretly collects a complete digital profile of your computer , including a device fingerprint, cookie sessions, and even passkeys. Device fingerprint: BlueKit records your IP address, web browser details, and device characteristics. Together, details such as screen size, operating system, and hidden hardware settings can form a “fingerprint” that helps distinguish one browser or device from another. Many modern security systems look for familiar devices to double-check that it’s really you trying to log in. So by stealing this background information alongside your password, an attacker can mimic your device to bypass security checks. Session cookies: When you log into a website like your email or online bank, the site doesn’t make you retype your password every time you open a new page. Instead, it places a tiny file on your device called a session cookie to recognize that you’ve already signed in. Think of a session cookie like a VIP wristband given to you at a concert entrance. Once the guard checks your ticket—your login—they give you a wristband. While you’re wearing that wristband, you can walk freely in and out of the venue without showing your ticket again. Instead of just stealing your ticket, BlueKit also steals the wristband itself . Once the attacker takes your session cookie, they can paste it into their own browser and walk straight into your active account. They don’t need to guess your password, and they don’t need to ask for a two-factor code. The website already thinks they are you. Description of BlueKit’s data-capturing capabilitie s Live demos using real credentials, shared by the BlueKit team 3. A built-in AI assistant What makes BlueKit especially interesting right now is that it comes with its own built-in, “no-rules” artificial intelligence. Think of it like a malicious version of ChatGPT, built directly into the scammer’s toolkit. Usually, AI tools have safety filters to prevent people from doing illegal things. BlueKit’s creators, however, have removed those guardrails, advertising that their custom AI will answer “even extreme prompts” and help with “fraud-related questions.” Instead of writing convincing scam emails from scratch, an attacker can simply ask the AI to write phishing emails and fake text messages. This is a huge development. BlueKit illustrates how advanced AI features are not just for legitimate businesses. They are being packaged and sold as standard features in cybercriminal services, making it easier for attackers to launch highly convincing attacks. BlueKit’s advertised AI capabilities AI features advertised on BlueKit’s website The business behind BlueKit BlueKit’s claimed customer numbers also point to a potentially significant revenue stream. On August 29, the operators announced that the service had passed 1,000 customers. Based on the advertised subscription prices, we can illustrate the potential revenue generated so far, although the actual distribution of subscriptions is unknown. BlueKit’s announcement claiming more than 1,000 customers If all 1,000 customers purchased one 7-day subscription at $250: $250,000 in gross revenue. If all 1,000 customers purchased one 30-day subscription at $940: $940,000 in gross revenue. If purchases were split roughly equally between the 7-day ($250), 14-day ($480), and 30-day ($940) plans: Approximately $557,000 in gross revenue. These are hypothetical calculations, but even so, the figures are a striking example of the economics behind phishing-as-a-service: operators can potentially generate hundreds of thousands of dollars in revenue by selling access to their infrastructure to other criminals. BlueKit’s advertised subscription prices What this means for you Phishing has officially evolved beyond obvious scam pages filled with typos and blurry logos. BlueKit combines convincing login pages, a built-in AI assistant, and subscription access to tools that once required more technical skills. Services like these make sophisticated phishing easier to launch, allowing scammers to generate a highly convincing, customized phishing attack from scratch in as little as 10 minutes. Ultimately, services like BlueKit mean that advanced, highly deceptive cyberattacks are no longer limited to elite hackers. They are now fast, cheap, and accessible to anyone with a few dollars to spare. Polished wording and familiar branding are not proof that a message or login page is genuine. Open the app or website yourself. If a message asks you to sign in, use the official app or a saved bookmark rather than the link in the email or message. Check the website address before signing in. Scammers can use lookalike addresses with small spelling changes, known as typosquatting. A password manager can help as it will only autofill logins on the correct site, while Malwarebytes Browser Guard can help block phishing pages. Use passkeys where available, and keep two-factor authentication enabled. These are still valuable protections, although some phishing techniques can capture sessions after a user completes a login. If you signed in through a suspicious link, secure your account through the official app or website. Change your password, review your account activity, and sign out of all sessions. Pro tip: Malwarebytes Scam Guard can also help you assess a suspicious message before you act on it. “One of the best cybersecurity suites on the planet.” According to CNET. Read their review →