SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
BlueKit sells account takeover from one dashboard with templates for 97 brands
BlueKit, a phishing-as-a-service kit Malwarebytes has tracked since April, runs lures for 97 brands in 176 variants from one dashboard. Its targets include corporate SSO gateways, Salesforce and GitHub, so buyers with little skill can aim polished lures at work accounts.
The Watch · Security desk

What happened
- Consumer templates cover Amazon, Apple, Google, Booking.com, Bank of America, American Express and crypto exchanges, plus OpenAI and Anthropic logins.
- Business templates extend to HubSpot and to logins for security services from Check Point, Citrix, Cloudflare and Cisco.
- An SMS sender added in August lets buyers send smishing texts from the same dashboard that runs their phishing emails.
- The operators say the SMS feature can send from local US phone numbers to make the texts look more trustworthy.
Why it matters
- exposure A phished login for a remote-access or security console opens the network behind it, so one victim on these templates exposes far more than a single mailbox.
- capability Lures sent by text land on staff phones, where the corporate email gateway that filters the rest of the campaign never inspects them.
- constraint Detection and training that count on spotting a sloppy page lose ground each time the operators push another template polish release.
A BlueKit buyer works from one panel [9]. The buyer picks a brand template, deploys the page, sends the lure by email or text, and collects what the victim hands over [9][5][11]. The operators advertise the pages as "pixel-perfect and ready to deploy in one click" [2]. Malwarebytes classes BlueKit as phishing-as-a-service built to automate and scale account hijacking [8]. It describes such platforms as making a convincing attack "as easy as signing up for a monthly service" [14].
Some of this is verified and some is sales copy. Malwarebytes' own analysis found the consumer and business templates [3][10]. The polish claim belongs to the operators [2], as does the phone-number claim attached to the SMS feature [6]. The headline framing is Malwarebytes': an "AI-powered" kit that arms criminals with account-hijacking tools "in 10 minutes" [18].
The development record shows a maintained product. BlueKit first appeared on a prominent cybercrime forum in April [7]. Its operators announced a built-in SMS sender on their Telegram channel on July 26 [4] and released it on August 10 [5], 15 days later [17]. A September update reworked the templates and upgraded what Malwarebytes calls "the hidden technology they use to steal and manage sessions" [11]. Malwarebytes compared the release habit to a legitimate software company updating its apps [12].
BlueKit is one seller in a wider market. In August the same team reported a separate turnkey scam kit that bundled a command center, victim tracking and admin tools into one package [13]. Malwarebytes says the same pattern is well established in phishing [16].
Malwarebytes writes that scam emails are no longer limited to poorly written, easily spotted attempts [15]. When the kit supplies the page, the delivery and the session capture, the buyer's skill no longer decides how good the lure looks [9][11]. BlueKit takes sessions as well as credentials [11]. I would treat a confirmed hit from one of its pages as a session compromise and revoke active sessions along with resetting the password.
What to watch
- Reports tying BlueKit pages to live campaigns against named organisations would show actual use beyond the template catalogue.
- The next release notice on BlueKit's Telegram channel, especially any further change to session handling aimed at SSO logins.
- Action against the forum listing or Telegram channel BlueKit uses to sell the service and announce updates.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
As of September, BlueKit's template library supports 97 distinct brands across 176 variants.
- [2]
BlueKit's operators describe its phishing pages as "pixel-perfect and ready to deploy in one click."
ReportedSupportedSource: BlueKit operators, as quoted by Malwarebytes2 sources— create a free account to open themView cited source - [3]
BlueKit templates impersonate consumer services including Amazon, Booking.com, Google/Gmail and Apple; financial institutions including American Express and Bank of America plus numerous cryptocurrency exchanges; social platforms including TikTok, Facebook and X; and generative AI platforms including OpenAI and Anthropic.
- [4]
On July 26 the BlueKit team used its official Telegram channel to announce an upcoming built-in SMS sender.
- [5]
On August 10 the BlueKit team announced the release of the SMS sender, which lets scammers send smishing texts directly from the BlueKit dashboard alongside phishing emails.
- [6]
BlueKit's operators say the SMS update lets attackers use local US phone numbers, which could make messages appear more trustworthy.
ReportedSupportedSource: BlueKit operators, as reported by Malwarebytes2 sources— create a free account to open themView cited source - [7]
Malwarebytes has tracked BlueKit's development since the service first appeared on a prominent cybercrime forum in April.
- [8]
BlueKit is a phishing-as-a-service (PhaaS) toolkit designed to automate and scale account hijacking.
- [9]
BlueKit allows attackers to manage entire phishing campaigns through a single dashboard without needing deep technical knowledge.
- [10]
Malwarebytes found BlueKit support for business infrastructure and single sign-on gateways, including Salesforce, HubSpot, GitHub, and security services including Check Point, Citrix, Cloudflare and Cisco.
- [11]
A September BlueKit update improved the fake website templates to look more convincing and "upgraded the hidden technology they use to steal and manage sessions."
- [12]
Malwarebytes said BlueKit's creators constantly add new features, much like a legitimate software company releasing updates for its apps.
- [13]
In August, Malwarebytes reported on a separate turnkey scam kit that bundled the command center, victim tracking and administrative tools into a ready-to-use package.
- [14]
Malwarebytes says cybercriminals now use complete, subscription-based platforms that make launching convincing attacks "as easy as signing up for a monthly service."
- [15]
Malwarebytes says scam emails are no longer limited to poorly written, easily spotted phishing attempts.
- [16]
Malwarebytes says the pattern of criminals buying ready-made services instead of building their own infrastructure is well established in phishing.
- [17]
BlueKit's SMS sender shipped 15 days after it was announced.
- [18]
Malwarebytes' report headline: "AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes."
Sources
1 independent publisher whose own reporting we read for this story.
- malwarebytes.comAI-powered phishkit arms criminals with account-hijacking tools in 10 minutes
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.