Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands | TechRadar

Bluekit offers phishing-as-a-service with a twist Discover insights about researchers discover new all-in-one ‘bluekit’ phishing kit capable of bypassing enterp

TechnologyInnovationBest PracticesGuideTutorial
Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands | TechRadar
Listen to Article
0:00
0:00
0:00

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

(Image credit: Image: Generated with Google Gemini)

Researchers have discovered a complex new phishing kit

Bluekit offers phishing in a software-as-a-service package

An entire campaign can be centralized and automated, and assisted by AI

Bluekit is a new phishing kit uncovered by Varonis Threat Labs researchers, who reviewed the kit first hand to explore its capabilities.

The phishing kit has a broad range of dangerous capabilities, including the ability to mimic over 40 well-known brands, geolocation emulation, and an AI-assistant to walk you through an attack.

Bluekit is highly professionalized, and offers attackers a sophisticated all-in-one dashboard for launching a phishing campaign.

This devious VENOM phishing campaign targets business executives by name — so watch what you click on

How businesses can defend themselves against the rise of ‘phishing as a service’

The fake Rolex problem: How AI turned amateur attackers into nation-state threats

Rather than congregating each component for a phishing attack from different vendors, Bluekit acts in a similar way to a software-as-a-service platform, with a dashboard that centralizes and automates phishing workflows, significantly reducing the barrier for entry to potentially devastating phishing attacks.

Bluekit handles domain registration, site hosting, and data exfiltration on a single panel, and offers emulation of popular global platforms, including i Cloud, Apple ID, Gmail, Outlook, Hotmail, Yahoo, Proton Mail, Git Hub, Twitter, Zoho, Zara, and Ledger. Offering such a wide range of targets allows attackers to quickly pivot between targets, run recognizable but local campaigns, and even run attacks simultaneously.

The platform also integrates the Telegram messaging app to offer real-time alerts on successful exfiltration.

Varonis also explored the platforms’ AI assistant, which they say could be potentially jailbroken variants of Llama, GPT-4.1, Sonnet 4, Gemini, and Deep Seek. In testing, the AI agent was capable of drafting “skeleton” phishing emails that required little modification in order to create convincing localized lures. Typically, an official AI model would reject any attempts to draft a phishing email, but by using jailbroken versions these guardrails are removed.

A screenshot from the Bluekit dashboard showing the variants of jailbroken AI models available for use by the integrated AI assistant. (Image credit: Varonis)

In order for the automated attack to avoid detection, Bluekit also includes features that allow it to cloak itself to avoid bot-detection tools, and can prevent analysis checks by preventing site access to headless user agents, headless resolutions, bad fingerprints, proxies and virtual private networks (VPNs). Device access can also be filtered to desktop or mobile only.

This popular app builder is being abused to trick users - here's what we know

Spotting the spyware: How modern spies are weaponizing phishing

'The breadth of targeted cloud platforms continues to expand': Google's security team takes a look at how Shiny Hunters have rolled out so many SSO scams recently

During their testing, the researchers noted that Bluekit is being actively updated with new features, rapidly expanding its abilities and making the kit an increasingly potent tool for attackers. “The feature set keeps evolving as we track it, and if that pace continues with broader adoption, Bluekit is likely to surface in future campaigns,” the researchers said.

A screenshot of the Bluekit dashboard, showing the centralized panel an attacker would see when launching or monitoring a campaign. (Image credit: Varonis)

As AI is lowering the barrier for entry into cybercrime, so too are all-in-one attacking platforms such as Bluekit.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Benedict is a Senior Security Writer at Tech Radar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.

You must confirm your public display name before commenting

1 Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands

2 Legendary Deus Ex and Thief director Warren Spector is back with a new game — it’s a stealth-heist-em-up called Thick as Thieves, and even the price is a steal at just five bucks on Steam

3'Bond often starts without a gun in the movies, and he can solve that creatively' — 007 First Light combat designer on the method behind its bombastic brawls

4'Now this is podracing!' — Star Wars: Galactic Racer will officially launch in October as developer shares preorder details

5'A premium World Cup experience': these are the 3 OLED TVs I'd recommend if you're looking for the best way to watch the World Cup — I've tested and compared them all to the competition personally

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.