Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Bluekit Phishing as a Service (PhaaS)

0
Medium
Published: 06/16/2026 (06/16/2026, 23:44:00 UTC)
Source: AlienVault OTX General

Description

BlueKit operates as a mature commercial Phishing-as-a-Service platform offering 87 ready-made phishing kits targeting banks, cloud services, cryptocurrency exchanges, and global brands. The platform features subscription-based access, automated account takeover capabilities, peer-to-peer infrastructure for stealth, and integrated anti-detection tooling. BlueKit supports credential harvesting, session hijacking, and automated post-compromise workflows including password resets and passkey enrollment. The platform includes bulk SMS phishing capabilities, Telegram notifications, hardware wallet seed phrase harvesting, and integration with anti-detect browsers. Operating through Tor and clearnet domains with cryptocurrency payments, BlueKit employs a reseller model enabling white-label redistribution. The platform significantly lowers technical barriers for cybercriminals while providing enterprise-grade phishing infrastructure, posing critical threats to financial institutions, cloud environments, and cryptoc...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/17/2026, 08:30:10 UTC

Technical Analysis

BlueKit is a mature commercial phishing platform that offers 87 phishing kits targeting various high-value sectors including banking, cloud services, and cryptocurrency exchanges. It features subscription-based access and advanced capabilities such as automated account takeover, session hijacking, and post-compromise automation. The platform uses peer-to-peer infrastructure and anti-detection tools to evade defenses and operates through both Tor and clearnet domains with cryptocurrency payment options. Its reseller model enables white-label redistribution, expanding its reach. BlueKit's capabilities include credential harvesting, bulk SMS phishing, Telegram notifications, and hardware wallet seed phrase theft, making it a comprehensive phishing infrastructure that significantly lowers the technical barrier for attackers.

Potential Impact

The platform enables cybercriminals to conduct large-scale phishing campaigns with advanced automation and stealth features, increasing the risk of credential theft, account takeover, session hijacking, and cryptocurrency theft. Financial institutions, cloud service providers, and cryptocurrency exchanges are primary targets, potentially leading to significant financial losses and compromise of sensitive user data. The availability of bulk SMS phishing and hardware wallet seed phrase harvesting further expands the attack surface and potential impact.

Mitigation Recommendations

No official patch or remediation exists as this is a criminal service rather than a software vulnerability. Organizations should focus on phishing detection and prevention measures, user education, and multi-factor authentication to mitigate risks. Since BlueKit operates via Tor and clearnet and uses anti-detection techniques, defenders should enhance monitoring for phishing indicators and suspicious account activities. There is no vendor advisory or official fix related to this threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas"]
Adversary
null
Pulse Id
6a31dfc08e2c3f8e5019ab67
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash2f08ce5a60ec42ffaaac5c46ba18bac8

Domain

ValueDescriptionCopy
domainbluekit.cc
domainbluekit.pk
domainbluekit.su
domainbluekit.ws
domainbluekitsmi6sd5mjurh3l7n7oeizbedoe2hw2lsljtb5nbxiul6hzkqd.onion

Threat ID: 6a3257ee0b89be6888fed03f

Added to database: 06/17/2026, 08:16:46 UTC

Last enriched: 06/17/2026, 08:30:10 UTC

Last updated: 07/30/2026, 13:29:32 UTC

Views: 113

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses