BlueKit Phishing-as-a-Service Leverages AI for Rapid Account Hijacking
The BlueKit phishing-as-a-service (PhaaS) toolkit empowers cybercriminals to launch sophisticated account-hijacking campaigns within minutes, utilizing a vast template library and minimal technical expertise.

Cybercriminals no longer need to build their own infrastructure from scratch to launch convincing online scams. The evolving cybercrime economy increasingly offers ready-made services that handle the complex work, and phishing-as-a-service (PhaaS) platforms exemplify this trend. One of the most potent examples is BlueKit, a toolkit designed to automate and scale account hijacking operations, allowing attackers to manage entire phishing campaigns through a single dashboard without requiring deep technical knowledge.
Malwarebytes research has been tracking BlueKit's development since its emergence on a prominent cybercrime forum in April. The service has evolved significantly, demonstrating a growing capability to support sophisticated criminal operations. The operator behind BlueKit, known as "petrushka," has actively developed the platform, making it an accessible tool for a wide range of threat actors.
As of September, BlueKit boasts an extensive template library supporting 97 distinct brands across 176 variants. The operators market these phishing pages as "pixel-perfect and ready to deploy in one click." This extensive library targets both consumer and business platforms, aiming to maximize victim engagement through familiar branding.
The phishing kit templates cover a broad spectrum of services. This includes major consumer platforms like Amazon, Google/Gmail, and Apple; financial institutions and cryptocurrency exchanges such as American Express, Bank of America, and numerous crypto wallets; and popular social media platforms like TikTok, Facebook, and X. Notably, BlueKit also offers templates designed to steal login details for generative AI services, including OpenAI and Anthropic, reflecting the growing importance of these platforms in the digital landscape.
One of the key features of BlueKit is its ability to automate the entire phishing process. Attackers can select a target brand, customize the campaign, and deploy it rapidly. The toolkit includes a command center for managing operations, tools for tracking victims, and administrative functions, all integrated into a user-friendly interface. This turnkey approach significantly lowers the barrier to entry for aspiring cybercriminals.
The sophistication of BlueKit lies in its ability to mimic legitimate services with high fidelity. The "pixel-perfect" templates ensure that phishing pages are visually indistinguishable from their authentic counterparts, increasing the likelihood of users falling victim. The inclusion of AI-related services in its template library highlights the adaptability of these phishing kits to emerging technological trends.
BlueKit's success is a testament to the commoditization of cybercrime tools. By providing a comprehensive, subscription-based service, it enables less technically skilled individuals to conduct large-scale, sophisticated attacks. This trend poses a significant challenge for cybersecurity professionals, who must contend with an ever-increasing volume of highly convincing phishing attempts.
The implications of BlueKit extend beyond simple credential theft. Account hijacking can lead to identity theft, financial fraud, and further compromise of an individual's or organization's digital assets. The rapid deployment and broad targeting capabilities of BlueKit make it a significant threat in the current cybersecurity landscape.