:

BLUEKIT PHISHING KIT ADDS BROWSER-IN-THE-MIDDLE THEFT

SECURITY DESK1 MIN READ
THU, JUN 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The Bluekit phishing-as-a-service platform has expanded its capabilities with browser-in-the-middle technology for stealing login credentials. Security researchers identified nearly 70 new hostnames associated with the service over the past week.

Bluekit continues to evolve as a commercial phishing platform, now incorporating browser-in-the-middle (BitM) techniques to intercept and capture user credentials with greater sophistication. The BitM approach positions the attacker's infrastructure between a victim and legitimate websites, allowing real-time interception of login data and session tokens. This advancement moves beyond traditional phishing, which typically relies on static credential capture forms. Researchers discovered approximately 70 additional hostnames linked to Bluekit deployments in a single week, suggesting active distribution and expansion. The platform operates as a phishing-as-a-service model, offering tooling and hosting to lower-skilled attackers. The addition of BitM capabilities represents a significant technical upgrade for the kit, enabling attackers to bypass certain security measures and capture data that standard phishing pages cannot access. Organizations should monitor for Bluekit-related phishing campaigns and educate users on credential verification practices.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A threat actor claims to have stolen employee databases from Microsoft Azure infrastructure across multiple Fortune 500 companies using compromised credentials. The stolen records are now being offered for sale.

3H AGOAI Desk

Pokémon Center notified customers in the UK and Germany of a data breach affecting personal and order information. The breach occurred through third-party logistics provider CEVA Logistics, which was compromised by hackers.

4H AGOSecurity Desk

Australia's major supermarket chains Coles and Woolworths have confirmed testing facial recognition technology in their stores, sparking privacy concerns from advocates who warn the systems could normalize mass surveillance.

7H AGOAI Desk

Breaches at shipping companies handling hardware wallet deliveries have compromised customer personal data, increasing risk of targeted physical theft and attacks against cryptocurrency owners.

10H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.