Until recently, setting up a phishing campaign required technical knowledge, time, and access to several different services. That is changing. Researchers from the cybersecurity firm Varonis have discovered Bluekit, a platform that turns phishing into a turnkey service — with artificial intelligence included.

Bluekit control panel, the AI phishing platform that automates fraudulent campaigns

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

What is Bluekit and Why is it Relevant?

Bluekit is what is known as Phishing-as-a-Service (PhaaS): a subscription tool that any cybercriminal can hire to launch phishing campaigns without needing to know how to program. What makes Bluekit special is that it centralizes the entire process in a single control panel:

The AI That Helps Write Phishing Emails

The most concerning detail about Bluekit is its artificial intelligence assistant. The platform includes an AI panel that allows scammers to automatically generate phishing email drafts. What sets this system apart is that it does not use standard commercial models — it uses modified versions of open-source AI models from which security filters have been removed.

In other words: while ChatGPT or Claude would refuse to help draft a fraudulent email, the version Bluekit uses has no such restraint. The result is an assistant that generates the campaign structure — email subject, body text, fake link — with minimal effort from the attacker.

The Varonis researchers who analyzed the internal system note that, for now, the assistant generates skeletons with placeholders that must be filled in manually, but the platform is under active development and evolving rapidly.

Which Services Do These Fake Pages Imitate?

Detected templates include imitations of iCloud, Apple ID, Gmail, Outlook, Hotmail, Yahoo, ProtonMail, GitHub, Twitter, Zoho, Zara, and Ledger. The designs include real logos and are visually indistinguishable from the original pages.

How to Protect Yourself?

Most importantly: multi-factor authentication via SMS or apps is no longer enough against techniques like the one Bluekit uses. Expert recommendations suggest:

⚠️ If you have received an email from iCloud, Gmail, Outlook, or any bank asking to verify your account, do not click. Paste it into the ORTSLAB scanner and you will know in seconds if it is legitimate or a trap.
Ransomware: qué es, cómo llega a tu ordenador y qué hacer si te infectas