News Article · Jun 26, 2026 at 6:38 AM
3 min read 0
Member
Bluekit Phishing Kit Adds Browser-in-the-Middle Tactic as Russia Targets Activists via Cellebrite
Security #phishing #Cisco #Russia #browser-in-the-middle #Cellebrite #Edge extension #Bluekit #rrweb

Bluekit Phishing Kit Adds Browser-in-the-Middle Tactic as Russia Targets Activists via Cellebrite

Bluekit phishing-as-a-service adds browser-in-the-middle for real-time session theft, while Russia uses Cellebrite to access activist phones. Cisco SD-WAN flaws exploited months before disclosure.

Listen to this article 4 min

The Bluekit phishing-as-a-service platform has added browser-in-the-middle capabilities, according to a new report from Netcraft. Nearly 70 new hostnames tied to the service were identified in the past week alone. The technique gives attackers real-time access to victim sessions after login.

Bluekit first appeared in April with an AI assistant that supports multiple large language models including Llama, GPT-4.1, Claude, Gemini, and DeepSeek. The kit originally offered 40 templates targeting Outlook, Hotmail, Gmail, Yahoo, ProtonMail, iCloud, GitHub, and Ledger. Netcraft reports that Bluekit now uses the open-source JavaScript library rrweb to serialize the page's DOM and stream it over a WebSocket to the attacker. The attacker's browser loads the legitimate login page and relays input between victim and service. Authentication completes in the attacker's browser, granting a valid session token and unlimited access.

New Anti-Analysis Features in Bluekit

Before stealing credentials, Bluekit runs a comprehensive victim qualification system to filter out researchers and security crawlers. The latest version includes:

  • Randomized CSS filters to defeat screenshot-based detection.
  • A large, frequently changing obfuscated JavaScript bundle over 1 MB in size.
  • Custom CAPTCHA that imitates Cloudflare or the target brand.
  • Browser fingerprinting for RAM, CPU cores, screen resolution, language, headless browser detection, and anti-fingerprinting extensions.
  • WebRTC-based IP mismatch detection to identify users behind proxies or VPNs.

Netcraft notes that rrweb itself is legitimate and widely used for session replay. Its presence alone is not an indicator of compromise. Latency on keyboard input and mouse clicks may signal a BitM attack.

Phone Cracking, Dairy Attacks, and Sandbox Escape

Separately, Russian authorities used Cellebrite phone-cracking tools to access the phone of human rights activist Andrey Pivovarov, according to Citizen Lab. This occurred even after the company canceled its contract with Russia. The incident underscores how forensic tools can outlive official agreements once in state hands.

A dairy manufacturer in Russia's Bashkortostan republic was also disrupted by a cyberattack, as reported by The Record. The incident follows a pattern of attacks on Russian food producers.

Researchers discovered a malicious Microsoft Edge extension that breaks out of the browser sandbox and installs ransomware. The extension abuses Native Messaging to bridge into the host operating system, according to TechRadar Pro.

A high-severity vulnerability in Cisco Catalyst SD-WAN Manager was exploited as early as March, months before its June disclosure, Google warned. The flaw allowed attackers to gain root access to affected devices.

Organizations facing these threats should monitor for unusual browser behavior, review extension permissions, and patch SD-WAN systems immediately. The Bluekit report provides signals including CSS filter manipulation, WebSocket connections on login pages, and WebRTC IP checks. But Netcraft advises these are not standalone indicators of compromise.

Fact check

  • Bluekit added browser-in-the-middle capabilities using the rrweb JavaScript library.

    verified · source

  • Nearly 70 new hostnames for Bluekit were identified over the past week.

    verified · source

  • Russian authorities used Cellebrite tools to access activist Andrey Pivovarov's phone after the contract with the company was canceled.

    reported · source

  • A high-severity vulnerability in Cisco Catalyst SD-WAN Manager was exploited as early as March 2026.

    reported · source

  • A malicious Microsoft Edge extension escapes the browser sandbox to install ransomware.

    reported · source

Source reporting (11)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 1323 users online: 0 registered, 1315 guests and 8 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Bingbot Googlebot Other Bot Other Spider SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 360