AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes
What happened
In August, the Malwarebytes research team reported on a new malicious turnkey kit that makes it possible for almost anyone to launch a sophisticated online scam. BlueKit puts account-hijacking tools in more criminals’ hands, making it easier to target you with convincing fake login pages and scam messages.
The kit was not simply a fake website. It bundled the command center, victim tracking, and administrative tools into a ready-to-use package, reducing the technical knowledge needed to operate a scam.
The discovery highlights an important feature of the cybercrime economy: criminals don’t necessarily need to build their own infrastructure from scratch. Instead, they can buy ready-made services that handle much of the complicated work for them.
Sources & evidence
- Malwarebytes Labs Reporting source
AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes ↗
https://www.malwarebytes.com/blog/threat-intel/2026/10/ai-powered-phishkit-arms-criminals-with-account-hijacking-tools-in-10-minutes