A subscription service for stealing your accounts
The most consequential cybercrime story of the moment is not a breach at a Fortune 500 company — it is a product launch on a criminal forum. Researchers at Malwarebytes have spent six months tracking BlueKit, a phishing-as-a-service platform that first surfaced in April 2026 and has since matured into one of the most complete account-hijacking operations available to anyone willing to pay for it1. According to the service's own operators, a buyer can connect a domain and have a fully functional phishing site ready in roughly ten minutes, with subscriptions starting at $250 for seven days1.
That price point deserves attention on its own. For less than the cost of a weekend hotel stay, a person with no coding ability can rent the same offensive infrastructure that was once the province of skilled attackers. The kit's operators market their fake login pages as "pixel-perfect" and deployable with a single click1. As of September, the platform offered 97 distinct brand templates across 176 variants — impersonating Amazon, Google, Apple, Bank of America, American Express, TikTok, Facebook, X, and even OpenAI and Anthropic sign-in pages12.
Why the usual advice is no longer enough
For years, the standard consumer defense against phishing has been: watch for bad grammar, check the sender, and turn on two-factor authentication. BlueKit is purpose-built to defeat all three assumptions.
First, the kit does not merely steal passwords. When a victim logs into a fake page, BlueKit quietly harvests a complete profile of their device — IP address, browser characteristics, screen size, operating system — forming a "fingerprint" that can be replayed to fool security systems that trust familiar devices1. More importantly, it steals session cookies, the tokens that tell a website you have already signed in. An attacker who obtains a session cookie can paste it into their own browser and walk into the victim's active account without a password and without ever triggering a two-factor prompt1.
Second, the AI angle. BlueKit ships with its own built-in, guardrail-free AI assistant that its creators advertise as willing to answer "even extreme prompts" and "fraud-related questions"1. Earlier independent analysis by Varonis Threat Labs found the assistant runs on an "abliterated" Llama model — an open-weight AI with its safety filters deliberately stripped out — with GPT-4.1, Claude Sonnet, Gemini, and DeepSeek variants listed as options34. The significance here is architectural: criminals no longer need to jailbreak mainstream chatbots to generate convincing scam copy; they can buy an uncensored model pre-integrated into their attack dashboard4.
To be fair to the threat-modeling, the AI is not yet the finished copilot its marketing suggests. Varonis researchers who tested the assistant against a detailed executive-phishing scenario found it produced structured campaign drafts riddled with placeholders rather than ready-to-use lures34. That gap, however, is closing on the vendor's own release schedule.
Scam texts from local numbers
For consumers, the most alarming BlueKit development landed this summer. On July 26, the operators announced an SMS sender on their Telegram channel; by August 10, it was live1. This means subscribers can now fire smishing — scam text — campaigns directly from the same dashboard that manages their fake login pages. The tool's advertised ability to send texts from local US phone numbers is a meaningful escalation, because a message that appears to come from an in-area number carries a presumption of legitimacy that a foreign or unknown sender does not1.
The practical effect is that a scam text claiming to be from your bank, your email provider, or a package delivery service may lead to a page indistinguishable from the real thing, hosted on a fresh domain, monitored in real time, with stolen session data piped to the attacker's Telegram within seconds of your clicking "sign in." Telegram is set as the default exfiltration channel, meaning stolen credentials flow to an attacker-controlled chat in real time and are genuinely hard for defenders to trace3.
From your inbox to your company's SSO
It would be a mistake to file BlueKit under "consumer nuisance." The kit's template library extends deep into corporate infrastructure: it supports single sign-on gateways and impersonation pages for Salesforce, HubSpot, GitHub, Check Point, Citrix, Cloudflare, and Cisco1. A September update improved both the realism of the fake pages and the underlying session-theft machinery2.
BlueKit also fits a documented pattern rather than an anomaly. In September, Microsoft tied a separate toolkit, EvilTokens, to campaigns that compromised more than 12,000 inboxes across over 10,000 organizations worldwide, with that kit using AI to tailor lures to a victim's job and to sift stolen mailboxes for finance staff and executives5. Microsoft's Digital Crimes Unit separately detailed how the Tycoon2FA phishing service enabled campaigns reaching over 500,000 organizations per month before a takedown with Europol, using the same adversary-in-the-middle trick of intercepting session cookies to bypass MFA6. The FBI, for its part, published a public service announcement in May 2026 warning about Kali365, a platform that captures OAuth tokens to gain persistent Microsoft 365 access without ever touching a password7. BlueKit's innovation is not its techniques — it is the packaging, the price, and the pace of its update cycle.
The industrialization of identity theft
Reading across this reporting, the economics are the real story. Malwarebytes estimates that BlueKit's operators can plausibly generate hundreds of thousands of dollars in revenue selling access to their infrastructure, with hypothetical subscription math showing how a PhaaS vendor scales2. Meanwhile, broader industry data shows 82% of phishing toolkits advertised on underground markets now mention deepfake capabilities and roughly three-quarters reference AI, according to Egress research, while KnowBe4 found 86% of phishing campaigns now involve some form of AI, up from 80% in 202489.
This is what the industrialization of identity theft looks like. The person who steals your Amazon login, drains your crypto wallet through a fake Trezor page, or uses your Facebook session to run marketplace scams against your own friends and family1 may have never written a line of code. They selected a template from a dropdown menu, paid a subscription fee, and let an uncensored AI draft the message that convinced you to click.
What still works for ordinary users
The defense guidance from researchers is sober but not hopeless. Passkeys and two-factor authentication remain worth enabling — even though kits like BlueKit can capture sessions after a login completes, strong authentication still raises the cost of the initial compromise1. A password manager will only autofill on the genuine domain, which neutralizes most typosquatted lookalike sites1.
The single most durable habit is behavioral: if a message — email or text — asks you to sign in, do not use its link. Open the official app or a saved bookmark instead1. And if you suspect you have entered credentials through a suspicious page, act through the real site: change the password, review account activity, and sign out of all sessions everywhere1.
For compromised corporate accounts, Microsoft's guidance is more urgent: revoke refresh tokens, review mailbox rules and registered devices, and consider temporarily disabling the account — because stolen tokens can remain usable for up to an hour after standard revocation5.
The uncomfortable takeaway is that polish is no longer proof of anything. The blurry-logo, typo-ridden phishing page is a historical artifact. In its place is a subscription business with a roadmap, a Telegram marketing channel, and an AI assistant that never says no — and the next version is always a few weeks away12.
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.
Sources
- 01Internet Crime Complaint Center (IC3) — ic3.gov
- 02Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale — microsoft.com
- 03InboxPrime AI: New Phishing Kit Fueling Scalable, AI-Powered Cybercrime — abnormal.ai
- 04AI Now a Staple in Phishing Kits Sold to Hackers — msspalert.com
- 05Warning: New Phishing Kit Targets Hundreds of Organizations — blog.knowbe4.com
- 06New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale — thehackernews.com
- 07New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks — hackread.com
- 08Google Ads Campaign Spreads Fake Security Alerts That Lock Browsers and Push Malware — cybersecuritynews.com
- 09AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes — malwarebytes.com
- 10AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes - Malware News - Malware Analysis, News and Indicators — malware.news
- 11TikTok phishing: How to spot fake login and verification pages — malwarebytes.com
- 12The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine — cybersecuritynews.com
- 13Bluekit Phishing Kit Automates Domains, 2FA Lures, and Session Hijacking in One Panel — cybersecuritynews.com
- 14Bluekit phishing kit enables automated phishing with 40+ templates and AI tools - Security Affairs — securityaffairs.com
- 15Bluekit Phishing Kit Turns Session Hijacking into a Point-and-Click Operation — ebuildersecurity.se