Bluekit, a phishing-as-a-service platform used to steal logins for major email and online accounts, has added a more advanced browser-in-the-middle technique that can hand attackers live authenticated sessions. Netcraft says the kit now uses the legitimate rrweb JavaScript library to stream a real browser session over WebSockets while relaying the victim’s interactions to the attacker, and it still includes anti-analysis features such as browser fingerprinting, WebRTC IP checks, obfuscated scripts, fake CAPTCHAs, and live victim monitoring. Reported targets include Outlook, Gmail, Yahoo, ProtonMail, iCloud, GitHub, and Ledger users.
Why it matters: This makes phishing pages harder to spot and can let criminals bypass normal login protections by stealing valid session tokens, not just passwords. Organizations should tighten phishing defenses, watch for suspicious login-session activity and WebSocket-based fake login pages, and remind users to be cautious with branded sign-in links and unusual page lag.
Bill Toulas
2026.06.25
100% relevant
This article establishes a distinct story about Bluekit's evolution into a browser-in-the-middle phishing platform, including specific new infrastructure growth and tradecraft changes that defenders may need to detect.
← Back to all stories