Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection
A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While Varonis Threat Labs first spotted and reported the platform earlier this year, it appeared to be in development at that time.
New data shows it is now fully active on a large scale. Cybersecurity firm Netcraft has reported this sudden rise, discovering around 70 active website names using the system in just one week.
How the Scam Works
Typical scams usually trick people by copying a website page or passing internet data back and forth. Bluekit changes this approach by using an attack method called Browser-in-the-Middle (BitM).
According to Netcraft researchers, the system loads the real login page, like a Microsoft login, inside a browser that the hackers control. An open-source software tool called rrweb then “records and streams live DOM interactions” to the victim over a WebSocket connection, researchers...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE