Skip to content
AI-Powered Phishing Kits Enable Rapid Credential Theft

AI-Powered Phishing Kits Enable Rapid Credential Theft

First seen 8 Oct 2026, 15:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 16:42 UTC
  • •BlueKit allows phishing attacks to be launched in under 10 minutes.
  • •The kit targets 97 brands with ready-to-use templates for various sectors.
  • •Misconfigured proxies are exposing attackers' infrastructures, complicating defenses.

A new AI-based phishing kit, BlueKit, has emerged, allowing cybercriminals to launch sophisticated scams in under 10 minutes. This kit provides a complete package including a control center, victim tracking, and administration tools, significantly lowering the technical barrier for attackers. BlueKit boasts a library of templates targeting 97 brands, including major services like Amazon, Google, and financial institutions. Concurrently, a misconfiguration in adversary-in-the-middle proxies has exposed attackers' infrastructures, revealing IP addresses through session cookies. This highlights the evolving landscape of phishing, where attackers can relay real-time traffic to legitimate services while capturing credentials. Microsoft has reported that such campaigns have impacted over 10,000 organizations, demonstrating the widespread nature of these threats. The rapid deployment of these phishing kits underscores the limited effectiveness of traditional domain blocking measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-01
BlueKit first appeared on cybercrime forums
The phishing kit was reported on a well-known cybercrime forum, marking its entry into the market.
Malwarebytes
2026-09-01
BlueKit library expanded to 97 brands
The phishing kit's library grew to include templates for 97 different brands, enhancing its targeting capabilities.
Malwarebytes
2026-10-08
Proxy misconfiguration exposes attacker infrastructure
A misconfiguration in adversary-in-the-middle proxies revealed the attacker's IP addresses through session cookies.
Ciberseguridadlatam

More articles in this cluster (2)

Following this threat?

Track Bluekit and Amazon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What brands are targeted by BlueKit?
BlueKit targets 97 brands, including major services like Amazon, Google, and various financial institutions.
How quickly can phishing attacks be launched?
Phishing attacks using BlueKit can be initiated in under 10 minutes.
What should organizations do to protect against these threats?
Organizations should enhance their phishing detection capabilities and monitor for unusual login attempts, especially from unfamiliar IP addresses.