Affected Systems

Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week. No specific vendor or product vulnerability; threat relies on social engineering and credential theft.

Exploitation Status

Active campaign. Bluekit PhaaS platform is operational with recent infrastructure expansion. Browser-in-the-middle (BitM) capability enables real-time session hijacking and bypasses MFA protections. Threat actors are actively deploying new phishing domains.

Business Impact

Increased phishing attack surface with enhanced evasion capabilities. Browser-in-the-middle functionality allows attackers to intercept session tokens and bypass multi-factor authentication, enabling account takeover even when MFA is enabled. Rapid infrastructure deployment (70 domains/week) indicates active campaign targeting enterprise credentials. SOC teams should expect increased phishing volume and more sophisticated credential theft attempts that evade traditional MFA controls.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update email security gateways and web proxies with threat intelligence feeds covering Bluekit infrastructure and newly registered phishing domains
  • Deploy phishing-resistant MFA methods (FIDO2/WebAuthn hardware tokens, passkeys) for privileged accounts and critical SaaS applications to mitigate browser-in-the-middle attacks
  • Enable conditional access policies requiring device compliance and trusted network locations for sensitive cloud service authentication
  • Conduct user awareness training focused on identifying sophisticated phishing pages and reporting suspicious login prompts or unexpected MFA requests
  • Monitor authentication logs for anomalous login patterns including impossible travel, new device registrations, and session token abuse following successful MFA challenges