Our security research team at ThreatWatch360 analyzed Bluekit’s centralized phishing ecosystem designed to streamline infrastructure deployment, session interception, Telegram-based notifications, and evasive phishing operations at scale.
Threat actors are increasingly shifting from standalone phishing kits toward fully managed Phishing-as-a-Service (PhaaS) ecosystems that provide infrastructure, automation, campaign management, and credential interception capabilities through centralized dashboards. Researchers observed Bluekit operating as a subscription-based phishing platform designed to simplify large-scale phishing deployment, domain management, reverse-proxy operations, and victim session handling through a commercially structured web interface.
What is Bluekit?
Bluekit is a commercial Phishing-as-a-Service (PhaaS) platform that enables threat actors to deploy phishing campaigns using centrally managed infrastructure, custom domains, hosted phishing templates, and automated campaign workflows. The platform’s infrastructure and operational model strongly suggest that affiliates are not required to self-host phishing pages independently. Instead, Bluekit appears to centralize hosting, routing, campaign deployment, and operational tooling through a unified management platform.
Observed functionality indicates support for:
- Multi-brand phishing template deployment
- Reverse-proxy style phishing operations
- Streamed credential interception workflows
- Automated domain provisioning
- Hosted phishing infrastructure
- Telegram notification integrations
- Session handling and victim management
- Anti-detect browser integrations
- Subscription-based operational access
The platform’s operational model strongly suggests affiliates are not required to independently manage backend phishing infrastructure, significantly lowering the technical barrier for conducting large-scale phishing campaigns.

Figure 1 — Bluekit phishing-as-a-service landing page.
Centralized Dashboard Architecture Simplifies Phishing Operations
Once authenticated, affiliates gain access to a centralized operational dashboard designed to manage phishing infrastructure, victim sessions, domain provisioning, campaign deployment, and operational analytics.
The interface exposes multiple operational modules including:
- Domains
- Sites
- Mammoths
- Wallet
- Integrations
- Subscription management
Notably, the platform repeatedly references “mammoths,” which researchers assess likely refers to captured victims, intercepted sessions, or harvested accounts. Similar terminology has previously appeared within underground phishing and credential theft ecosystems where operators internally classify compromised users or active sessions under alternative naming conventions.
Researchers additionally observed deployment metrics, operational telemetry, and infrastructure management workflows resembling legitimate SaaS analytics platforms. This operational structure demonstrates how modern phishing ecosystems increasingly mimic commercial cloud services to simplify affiliate onboarding and scale phishing operations.

Figure 2 — Bluekit affiliate dashboard exposing centralized campaign management capabilities.
Bluekit Automates Domain Provisioning and Infrastructure Rotation
Bluekit provides integrated domain onboarding workflows designed to streamline phishing infrastructure deployment and reduce operational friction for affiliates.
Bluekit support for:
- Direct domain purchases
- External domain connections
- Subdomain provisioning
- Automated DNS workflows
- Cloudflare-integrated nameserver management
The platform indicates domains can become operational within minutes after DNS propagation completes, enabling rapid phishing deployment and infrastructure rotation during takedown events or blocklisting operations.
This operational model allows threat actors to continuously rotate phishing infrastructure, maintain campaign resiliency, and sustain phishing operations while avoiding disruption from security vendors, blocklists, and takedown actions.
Researchers additionally observed references to multiple associated domains and onion-based infrastructure, suggesting Bluekit likely maintains both clearnet and Tor-accessible operational environments designed to improve operational continuity.

Figure 3 — Bluekit domain provisioning and infrastructure management workflow.
Streamed Credential Interception Suggests AiTM Phishing Operations
Bluekit’s site deployment workflow provides additional insight into the platform’s phishing capabilities and reverse-proxy architecture.
Our team observed phishing templates impersonating multiple widely used platforms and service providers, including Apple and iCloud, Gmail, Outlook, ProtonMail, Yahoo, Zoho, and GitHub. The targeted brands indicate a strong focus on enterprise email services, cloud-based identity platforms, developer ecosystems, and high-value user accounts commonly leveraged during credential theft and account takeover operations.
The platform additionally exposes a selectable “streamed” operational mode during phishing deployment workflows. While Bluekit does not publicly document this capability, researchers assess the terminology likely refers to real-time adversary-in-the-middle (AiTM) phishing operations capable of dynamically intercepting authentication sessions during victim interaction.
This operational design significantly increases effectiveness against organizations relying on traditional MFA protections, particularly where active authentication tokens, cookies, or session artifacts can be intercepted and replayed.
Researchers also observed operational workflows consistent with:
- Session replay attacks
- Browser session hijacking
- MFA bypass operations
- Token interception
- Reverse-proxy phishing infrastructure

Figure 4 — Bluekit site deployment workflow exposing multi-brand phishing templates and streamed phishing modes.
Figure 5 — Demonstration of ProtonMail-themed phishing workflow deployment and streamed interaction handling.
Telegram Integrations and Anti-Detect Browser Support
Bluekit integrates directly with Telegram through configurable bot tokens and group-based notification workflows. This capability likely enables affiliates to receive real-time alerts whenever credentials, session tokens, or phishing interactions are intercepted.
Telegram continues to play a significant operational role across modern phishing ecosystems due to its automation capabilities, accessibility, and low operational overhead.
Researchers additionally observed integration support for Octo Browser, an anti-detect browser frequently used within cybercriminal ecosystems to manage multiple identities, evade fingerprinting protections, and operationalize stolen sessions. The integration appears designed to simplify importing captured sessions directly into isolated browsing environments.
The observed integration appears designed to simplify importing intercepted sessions directly into isolated browser environments for rapid account takeover operations.
This combination of real-time notifications, reverse-proxy phishing, and anti-detect browser support strongly suggests Bluekit is optimized for both credential theft and session hijacking workflows.

Figure 6 — Bluekit integrations panel exposing Telegram notification workflows and Octo Browser support.
Subscription-Based Monetization Model
Bluekit is monetized through a subscription-based pricing structure closely resembling legitimate SaaS licensing models. Researchers observed tiered access durations priced at approximately:
- 7 Days — $250
- 14 Days — $480
- 30 Days — $980
The platform advertises additional operational features including:
- Custom domain management
- Hosted phishing infrastructure
- Reverse-proxy support
- AI-assisted configuration
- Automated background tasks
- Instant activation workflows
- Voice interaction capabilities
The pricing structure indicates Bluekit is targeting operational affiliates rather than casual opportunistic actors. The elevated subscription costs suggest that operators expect affiliates to monetize campaigns through high-value credential theft, session hijacking, financial fraud, cryptocurrency theft, or business email compromise operations.
The commercialization model further demonstrates how modern phishing ecosystems increasingly function as managed criminal service providers rather than standalone malware distribution operations.

Figure 7 — Bluekit subscription tiers and operational feature segmentation.
What Security Teams Should Monitor
SOC teams, DFIR analysts, network defenders, and CISOs should closely monitor indicators associated with AiTM phishing infrastructure and session hijacking operations.
The ThreatWatch360 research team recommends monitoring for:
- Suspicious reverse-proxy phishing domains
- Rapid domain rotation patterns
- Abnormal authentication session reuse
- Unexpected MFA approval behavior
- Token replay anomalies
- Cloudflare-abusing phishing infrastructure
- Telegram-based phishing telemetry
- Suspicious browser session imports
- Lookalike domains impersonating cloud providers
- OAuth and identity abuse workflows
Organizations should additionally strengthen phishing-resistant MFA adoption, session monitoring, conditional access policies, identity telemetry analysis, and phishing infrastructure detection capabilities.
MITRE ATT&CK Mapping
Observed operational behaviors align with multiple MITRE ATT&CK techniques including:
| Technique | Description |
|---|---|
| T1566 | Phishing |
| T1078 | Valid Accounts |
| T1185 | Browser Session Hijacking |
| T1583 | Acquire Infrastructure |
| T1102 | Web Service |
| T1550 | Use Alternate Authentication Material |
| T1584 | Compromise Infrastructure |
The ThreatWatch360 research team observed Bluekit using clearnet and onion-based infrastructure along with Telegram-integrated workflows to support scalable and resilient phishing operations. The platform exposes capabilities including streamed phishing workflows, reverse-proxy infrastructure, automated domain rotation, session handling, multi-brand phishing templates, and anti-detect browser integrations designed to simplify credential theft and session hijacking operations.
We observed phishing templates impersonating multiple popular platforms including Apple, iCloud, Gmail, Outlook, ProtonMail, Yahoo, Zoho Mail, and GitHub, indicating a strong focus on enterprise email services, cloud platforms, and developer ecosystems.
Darkweb Monitoring and Exposure Intelligence
Phishing-as-a-Service ecosystems like Bluekit contribute directly to credential theft, session hijacking, business email compromise, and enterprise account takeover activity across underground ecosystems. Captured credentials and authentication sessions are frequently monetized through Telegram channels, darkweb marketplaces, and initial access broker networks.
ThreatWatch360 helps organizations identify phishing infrastructure, exposed credentials, impersonation campaigns, and malicious domains through capabilities including brand protection, darkweb monitoring, anti-phishing, anti-rogue operations, takedown services, domain monitoring, and social media monitoring. Early identification of phishing campaigns and exposed authentication assets can significantly reduce organizational exposure to account takeover and credential abuse operations.


