Affected Systems
Organizations using cloud services and SaaS platforms targeted by Bluekit phishing-as-a-service infrastructure. Approximately 70 new phishing hostnames deployed in the past week. No specific vendor or product vulnerability; threat relies on social engineering and credential theft.
Exploitation Status
Active campaign. Bluekit PhaaS platform is operational with recent infrastructure expansion. Browser-in-the-middle (BitM) capability enables real-time session hijacking and bypasses MFA protections. Threat actors are actively deploying new phishing domains.
Business Impact
Increased phishing attack surface with enhanced evasion capabilities. Browser-in-the-middle functionality allows attackers to intercept session tokens and bypass multi-factor authentication, enabling account takeover even when MFA is enabled. Rapid infrastructure deployment (70 domains/week) indicates active campaign targeting enterprise credentials. SOC teams should expect increased phishing volume and more sophisticated credential theft attempts that evade traditional MFA controls.
Urgency
🟠Within 24 hours
Recommended Actions
- Update email security gateways and web proxies with threat intelligence feeds covering Bluekit infrastructure and newly registered phishing domains
- Deploy phishing-resistant MFA methods (FIDO2/WebAuthn hardware tokens, passkeys) for privileged accounts and critical SaaS applications to mitigate browser-in-the-middle attacks
- Enable conditional access policies requiring device compliance and trusted network locations for sensitive cloud service authentication
- Conduct user awareness training focused on identifying sophisticated phishing pages and reporting suspicious login prompts or unexpected MFA requests
- Monitor authentication logs for anomalous login patterns including impossible travel, new device registrations, and session token abuse following successful MFA challenges
