[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1cUzlMk4TCKTvffEXq-y5rUwLZswP7YlG26Y17QnlfA":3},{"article":4,"iocs":44,"watch_terms":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"d8e095d7-f4fd-4a18-b76b-b43ccc6a8f4e","‼️ A threat actor operating under the alias petrushka is selling a phishing-as-a-service (PhaaS)...","a-threat-actor-operating-under-the-alias-petrushka-is-selling-a-phishing-as-a-se-6e2092","‼️ A threat actor operating under the alias petrushka is selling a phishing-as-a-service (PhaaS) platform called Bluekit.\n\nThe service offers 40+ phishing templates, Evilginx-based adversary-in-the-middle capabilities, 2FA bypass with geolocation and browser spoofing, antibot https:\u002F\u002Ft.co\u002FRlXwr8wx0g","A threat actor using the alias petrushka is offering a phishing-as-a-service (PhaaS) platform called Bluekit that includes 40+ phishing templates, Evilginx-based adversary-in-the-middle (AitM) capabilities, and 2FA bypass functionality with geolocation and browser spoofing features. The service represents a commoditization of advanced phishing and credential theft attacks, lowering barriers to entry for less-skilled attackers. Bluekit's anti-bot protection and sophisticated evasion techniques make it a significant threat to organizations relying on standard MFA deployments.","Threat actor petrushka sells Bluekit phishing-as-a-service with 2FA bypass.",null,"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2046717528211108020","https:\u002F\u002Fpbs.twimg.com\u002Famplify_video_thumb\u002F2046717051876556800\u002Fimg\u002F_Xp2_WxWFWMCeaNf.jpg","2026-04-21T22:27:39+00:00","2026-04-21T23:00:08.198202+00:00",8,[18,21],{"name":19,"type":20},"petrushka","threat_actor",{"name":22,"type":23},"Phishing-as-a-Service (PhaaS)","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":24,"icon":11,"name":26,"slug":27},"Malware","malware",[29,34,39],{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":35},{"id":36,"icon":11,"name":37,"slug":38},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":40},{"id":41,"icon":11,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[45,48],{"type":27,"value":46,"context":47},"Bluekit","Phishing-as-a-service platform with AitM and 2FA bypass capabilities",{"type":27,"value":49,"context":50},"Evilginx","Adversary-in-the-middle framework integrated into Bluekit",[]]