Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bluekit PhaaS Bypasses MFA to Steal Microsoft Credentials

Bluekit PhaaS Bypasses MFA to Steal Microsoft Credentials

Posted on June 26, 2026 By CWS

A newly operational Phishing-as-a-Service (PhaaS) platform named Bluekit has been identified, with cybersecurity experts at Netcraft uncovering around 70 active domains in just one week.

What is Bluekit?

Initially noted by Varonis Threat Labs as a developing threat, Bluekit has advanced into a full-fledged system capable of bypassing multi-factor authentication (MFA) to capture Microsoft login details in real time. Unlike traditional adversary-in-the-middle (AitM) tactics like Evilginx, which intercept traffic between the victim and the genuine site, Bluekit uses a Browser-in-the-Middle (BitM) approach.

The process involves loading a legitimate Microsoft login page within an attacker-controlled browser, streaming the page to the victim using rrweb, an open-source JavaScript tool originally intended for session replay and analytics.

The Mechanics of Bluekit’s Attack

Through its sophisticated method, victims interact with the actual Microsoft login page displayed in the attacker’s environment. Once the victim completes the authentication process, they log into the attacker’s active session rather than their own, thus bypassing Device Bound Session Credentials (DBSC), which usually provide some resistance to classic AitM attacks.

Bluekit operates through two main stages before capturing credentials. In the first phase, it conducts thorough anti-analysis checks on visitors, including browser fingerprinting and CAPTCHA techniques mimicking legitimate brands like Cloudflare. Those who pass these checks engage with a real-time interactive login page streamed from the attacker’s browser.

Implications for Cybersecurity

With Bluekit, the stolen session is created and utilized within the same browser, avoiding detection mismatches typical in reverse-proxy AitM attacks. Traditional MFA methods such as SMS codes and authenticator apps offer no defense, as the victim completes the whole login sequence within the attacker-controlled environment.

Security experts should be vigilant for specific indicators such as WebSocket connections relaying encrypted data on login pages, the presence of rrweb outside usual contexts, and custom CAPTCHAs with varied HTML structures.

Future Outlook

Bluekit’s use of rrweb marks another instance of threat actors leveraging trusted infrastructure to evade detection systems. Its presence alone does not signify a compromise; instead, organizations must consider surrounding contexts and signals. As Bluekit demonstrates, relying solely on MFA for credential protection is inadequate, highlighting the need for comprehensive session-level security measures and behavioral detection to counteract phishing threats effectively.

Cyber Security News Tags:Bluekit, Browser-in-the-Middle, Cybersecurity, cybersecurity news, MFA bypass, Microsoft credentials, Netcraft, Phishing, rrweb, security analysis, session consistency, session replay, threat detection, Varonis Threat Labs, WebSocket

Post navigation

Previous Post: Nebulock Secures $25M for Advanced AI Security
Next Post: Critical Linux Vulnerability Enables Unauthorized Root Access

Related Posts

Russian Hackers Exploiting 7-Year-Old Cisco Vulnerability to Collect Configs from Industrial Systems Russian Hackers Exploiting 7-Year-Old Cisco Vulnerability to Collect Configs from Industrial Systems Cyber Security News
North Korean Hackers Evade UN Sanctions Leveraging Cyber Capabilities, IT Workers and Crypto Activities North Korean Hackers Evade UN Sanctions Leveraging Cyber Capabilities, IT Workers and Crypto Activities Cyber Security News
VMware Fusion Flaw Allows Root Access Escalation VMware Fusion Flaw Allows Root Access Escalation Cyber Security News
Claude Opus 4.8: Revolutionizing AI Engineering Claude Opus 4.8: Revolutionizing AI Engineering Cyber Security News
Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore Criminal IP to Showcase ASM and CTI Innovations at GovWare 2025 in Singapore Cyber Security News
Smart Electric Vehicles Face Hidden Cyber Vulnerabilities Exposing Drivers to Risks Smart Electric Vehicles Face Hidden Cyber Vulnerabilities Exposing Drivers to Risks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware
  • Windows WalletService Flaw Could Lead to Privilege Escalation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark