Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

BlueKit sells account takeover from one dashboard with templates for 97 brands

BlueKit, a phishing-as-a-service kit Malwarebytes has tracked since April, runs lures for 97 brands in 176 variants from one dashboard. Its targets include corporate SSO gateways, Salesforce and GitHub, so buyers with little skill can aim polished lures at work accounts.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying BlueKit sells account takeover from one dashboard with templates for 97 brands
Generated illustration

What happened

  • Consumer templates cover Amazon, Apple, Google, Booking.com, Bank of America, American Express and crypto exchanges, plus OpenAI and Anthropic logins.
  • Business templates extend to HubSpot and to logins for security services from Check Point, Citrix, Cloudflare and Cisco.
  • An SMS sender added in August lets buyers send smishing texts from the same dashboard that runs their phishing emails.
  • The operators say the SMS feature can send from local US phone numbers to make the texts look more trustworthy.

Why it matters

  • exposure A phished login for a remote-access or security console opens the network behind it, so one victim on these templates exposes far more than a single mailbox.
  • capability Lures sent by text land on staff phones, where the corporate email gateway that filters the rest of the campaign never inspects them.
  • constraint Detection and training that count on spotting a sloppy page lose ground each time the operators push another template polish release.

A BlueKit buyer works from one panel [9]. The buyer picks a brand template, deploys the page, sends the lure by email or text, and collects what the victim hands over [9][5][11]. The operators advertise the pages as "pixel-perfect and ready to deploy in one click" [2]. Malwarebytes classes BlueKit as phishing-as-a-service built to automate and scale account hijacking [8]. It describes such platforms as making a convincing attack "as easy as signing up for a monthly service" [14].

Some of this is verified and some is sales copy. Malwarebytes' own analysis found the consumer and business templates [3][10]. The polish claim belongs to the operators [2], as does the phone-number claim attached to the SMS feature [6]. The headline framing is Malwarebytes': an "AI-powered" kit that arms criminals with account-hijacking tools "in 10 minutes" [18].

The development record shows a maintained product. BlueKit first appeared on a prominent cybercrime forum in April [7]. Its operators announced a built-in SMS sender on their Telegram channel on July 26 [4] and released it on August 10 [5], 15 days later [17]. A September update reworked the templates and upgraded what Malwarebytes calls "the hidden technology they use to steal and manage sessions" [11]. Malwarebytes compared the release habit to a legitimate software company updating its apps [12].

BlueKit is one seller in a wider market. In August the same team reported a separate turnkey scam kit that bundled a command center, victim tracking and admin tools into one package [13]. Malwarebytes says the same pattern is well established in phishing [16].

Malwarebytes writes that scam emails are no longer limited to poorly written, easily spotted attempts [15]. When the kit supplies the page, the delivery and the session capture, the buyer's skill no longer decides how good the lure looks [9][11]. BlueKit takes sessions as well as credentials [11]. I would treat a confirmed hit from one of its pages as a session compromise and revoke active sessions along with resetting the password.

What to watch

  • Reports tying BlueKit pages to live campaigns against named organisations would show actual use beyond the template catalogue.
  • The next release notice on BlueKit's Telegram channel, especially any further change to session handling aimed at SSO logins.
  • Action against the forum listing or Telegram channel BlueKit uses to sell the service and announce updates.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    As of September, BlueKit's template library supports 97 distinct brands across 176 variants.

  2. [2]

    BlueKit's operators describe its phishing pages as "pixel-perfect and ready to deploy in one click."

    ReportedSupportedSource: BlueKit operators, as quoted by Malwarebytes2 sources— create a free account to open themView cited source
  3. [3]

    BlueKit templates impersonate consumer services including Amazon, Booking.com, Google/Gmail and Apple; financial institutions including American Express and Bank of America plus numerous cryptocurrency exchanges; social platforms including TikTok, Facebook and X; and generative AI platforms including OpenAI and Anthropic.

Sources

1 independent publisher whose own reporting we read for this story.

  1. malwarebytes.com

    1 article · October 7, 2026

    AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories