A fake login page in ten minutes, 97 brands to pick from, 250 dollars a week
The unsettling thing about BlueKit is not the technology. It is the price list. Two hundred and fifty dollars buys a week, 480 buys a fortnight, 940 buys a month, and by the end of August the operators were claiming more than a thousand customers.
Malwarebytes researchers have followed the service since it appeared on a cybercrime forum in April and published their findings this week. What a subscriber gets is 176 ready-made fake sign-in pages covering 97 brands: Amazon, Google, Apple, Facebook, TikTok, American Express, Bank of America, OpenAI, GitHub, Cloudflare. The sellers advertise them as pixel-perfect and deployable in one click, roughly ten minutes from paying to having a live site. The same dashboard sends the phishing emails and text messages, and there is an AI assistant built in with the usual safety limits stripped out, so writing the bait no longer requires good English or any particular effort.
The sales pitch lists what it harvests: passwords, device fingerprints, session cookies and passkeys. The session cookie is the detail to understand. If the fake page is relaying your login to the real site as you type, then the code from your authenticator app gets passed through too, and what the attacker walks away with is the cookie your browser was handed afterwards, which is already signed in. A second step helps enormously, but it is not a force field.
So the dull advice is the right advice: never reach a sign-in page by clicking a link in a message. Open the app, or type the address yourself. And Tendvane's privacy and accounts check will show you which sign-ins on your PC still have nothing but a password behind them, which is where to start if you have been meaning to tidy that up.