BlueKit packages convincing login pages, campaign management and account-access theft into a subscription service. In research published on October 7, Malwarebytes traced the phishing toolkit’s development from its April appearance through later messaging and session-handling updates. The risk is not just a stolen password: a victim can finish a familiar-looking sign-in while the usable account session ends up under an attacker’s control.
That distinction matters after a suspicious login. Open the service independently, review recent activity and revoke unfamiliar sessions as well as changing an exposed password. A new password should not be your only recovery check.
From a template shop to a campaign control panel
The October report describes a service that combines impersonated websites with administration tools rather than selling a single fake page. Malwarebytes found templates aimed at consumer accounts, financial services, social networks and corporate sign-in systems. The operator’s September catalogue advertised 97 brands and 176 variants; those figures describe its claimed inventory, not 97 confirmed breaches or a count of victims.

The researchers also followed the release cycle. A built-in SMS sender was announced in July and released in August, adding text-message delivery to the dashboard. September changes covered page templates and session handling. An attacker can therefore change the lure and delivery channel while retaining the same campaign tools.
Operators advertise a roughly ten-minute setup and an AI assistant for producing scam messages. These are sales claims documented in the report, not timings or effectiveness established by Gridinsoft. The important change for recipients is that polished wording and consistent branding are affordable components of the service.
The real page can run in the wrong browser
Earlier firsthand research by Netcraft, published on June 25, explains a particularly revealing BlueKit technique: browser-in-the-middle phishing. The target’s genuine login page opens inside a browser controlled by the attacker. Its page structure and interactions are streamed to the victim through rrweb, a legitimate session-replay library repurposed for the attack.
The recipient sees an interactive page, but their typing and clicks travel back to the remote browser. Completing that flow authenticates the attacker’s browser session. The deception is therefore about where the login happens, not merely whether the logo or form looks convincing. The research describes a technique observed in June; it does not establish that every October BlueKit template uses the identical implementation.
This also explains why an approved second factor is not a complete incident check. In a relayed flow, the legitimate service may accept the login while the criminal controls the resulting session. It does not mean every MFA method or passkey can be defeated. Keep those protections enabled, check the address before authenticating, and do not mistake a familiar screen for proof of a trusted connection.
The ReliaQuest phishing case shows a different outcome: application access was blocked by device-trust controls after MFA approval. Session creation and access to sensitive applications are separate decisions.
Check account access, not just the password
If you only received a message, use a saved bookmark or the official app to check its claim. A Gridinsoft Website Reputation Checker lookup can add context for a suspicious address; a clean or unknown result does not authorize signing in. Avoid submitting credentials to test the page.
If you already entered credentials or approved a login through an untrusted page, use the service’s own security settings to change the exposed password, end unfamiliar sessions, and inspect recovery details, sign-in methods and connected applications. For a work account, tell the administrator which link and login were involved so they can check session and application access. The device-code phishing guide explains another way a real authentication flow can grant someone else access.
BlueKit’s October report documents the ongoing packaging of these capabilities. Its practical lesson is specific: a credible-looking login and successful MFA prompt can still leave an account-access problem to investigate.
References
- Malwarebytes Labs. “AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes.” October 7, 2026. Research report.
- Harry Everett. “Bluekit Phishing-as-a-Service: Browser-in-the-Middle, Evolved.” Netcraft, June 25, 2026. Technical analysis.

