New Bluekit phishing service includes an AI assistant, 40 templates
Key Points:
- Bluekit is a new phishing kit offering over 40 templates targeting popular email, cloud, developer, and cryptocurrency services, with integrated AI features to help cybercriminals draft phishing campaigns.
- The AI Assistant panel supports multiple models like Llama, GPT-4.1, Claude, Gemini, and DeepSeek, but currently produces draft outputs with placeholder content, indicating an early experimental stage.
- Bluekit consolidates domain registration, phishing page setup, campaign management, and real-time victim session monitoring into a single interface, allowing granular control over phishing page behavior and anti-analysis mechanisms.
- Stolen data is exfiltrated via private Telegram channels, and session monitoring tools enable operators to track victim activity post-login to optimize attacks.
- The kit is under active development with frequent updates, representing a growing trend of all-in-one phishing platforms that empower less skilled cybercriminals to conduct sophisticated attacks.