Cybercrime update graphic showing ShinyHunters and criminal forums trends.

BlueKit Browser-in-the-Middle, SaaS Breaches, and the Return of LeakBase

Table of Contents

Check your exposure

As everyone heads back to school, SpyCloud Labs is studying up on the latest cybercrime trends.

This month’s update covers:

Let’s get into it!

BlueKit PhaaS introduces Browser-in-the-Middle phishing

Our team at SpyCloud Labs has been monitoring new developments in enterprise-targeted phishing-as-a-service (PhaaS) kits. Now, many of these kits proxy session logins in order to bypass multi-factor authentication (MFA) protections and effectively capture and maintain access to sessions for enterprise accounts. This tactic is called adversary-in-the-middle (AiTM) phishing, and it’s been remarkably effective for attackers trying to gain access to enterprise cloud email and single sign-on (SSO) accounts. Because security teams have stepped up their monitoring for these AiTM tactics, actors are evolving PhaaS tactics to target victims via device code phishing and browser-in-the-middle phishing overlays. 

Browser-in-the-middle (BitM) is a new tactic which we are only (so far) tracking as being offered by a single PhaaS kit – BlueKit. BitM is a distinct evolution of AiTM: where AiTM proxies traffic between the victim’s browser and the real service, BitM loads the legitimate login page on attacker-controlled infrastructure and streams it to the victim, who interacts with it remotely. Live interactions are relayed using rrweb, which is a tool for recording and replaying users’ website interactions. 

The BlueKit panel combines subscriptions, site creation, automated domain purchasing and registration, campaign management (with over 80 pre-existing templates configured for different phishing styles, including device code and BitM), delivery tooling (including SMS sending and an AI assistant), and log tracking, into one interface. Phishing pages employ rigorous visitor qualification checks such as custom CAPTCHAs, browser fingerprinting, WebRTC/STUN IP enumeration, device filtering, RAM/CPU checks, and IP reputation filtering – all in an effort to block security scanners and researchers before serving malicious content. The kit’s use of the term “mammoth” for victim, its optional filter to block victims in CIS countries, and its advertisement on Russian forums (XSS, Exploit, T1erOne, and Lolzteam) all suggest a Russian-speaking origin for the BlueKit developers.

SpyCloud dashboard showing user activity and security metrics.

Screenshot of the BlueKit panel taken from their website. The panel features their Doraemon branding, which is consistent across their panel, website, and Telegram accounts. 

SpyCloud first recaptured BlueKit-stolen victim data on September 3, 2026. Since then we’ve collected almost a thousand messages attributable to BlueKit, documenting session captures against 37 organizations – including US and EU defense contractors, law firms, healthcare providers, multinational food distributors, construction companies, and more – arriving in two bursts, the first on September 4 and the second on September 10.

BlueKit victim organizations industry distribution chart for cybersecurity analysis.

In 38% of compromises we observed, BlueKit automatically enrolled its own TOTP authenticator on the victim’s account. That requires driving a real browser inside the account after login, and it leaves the attacker with persistent MFA access that survives a password reset. Remediation has to include auditing the account’s registered MFA methods (not just rotating the password), in addition to revoking all active sessions.

The BlgCloud leak displays “group chat behavior” on PwnForums

Over basically the entire month of August, a group of well-known actor accounts on PwnForums coordinated to trickle out a series of breaches allegedly stolen from customer instances of BlgCloud – a French business management SaaS platform. This group of 5 accounts have collectively posted 15 breaches (and counting) from BlgCloud accounts; every post in the series has been titled “BLGCloud Leak” with a corresponding number. The posters also claim to have access to many more BlgCloud customer instances, and are attempting to use the series of posts to monetize the exfiltrated data – either by getting paying customers to buy the unreleased breaches, enticing someone to buy the “access method and vulnerability” they claim to be using, or pressuring BlgCloud themselves to pay the hackers to stop releasing their customers’ data. 

This activity mirrors a tactic ShinyHunters often uses – pressuring individual customers of a major service provider to extort the service provider. In multiple cases, ShinyHunters has done this without ever compromising the centralized service provider’s production systems or finding a vulnerability in their service. They simply accessed a small subset of individual customer cloud service accounts, and attempted to use that to extort the centralized cloud service provider. 

What makes this series of breaches sort of interesting, is the fact that the 5 accounts all appear unrelated to each other, and they are not claiming an affiliation with any shared group in particular. These accounts are almost certainly coordinating somewhere in the background –  in some sort of private group chat – but they aren’t claiming any affiliation with one another and the only connection between these accounts on PwnForums is this clearly coordinated BlgCloud breach posting. It’s somewhat novel to have a group of cybercriminals posting in such a coordinated manner, without trying to further their cool group branding to gain clout or drive users to their shared Telegram channel where they advertise new data for sale.

SpyCloud cybersecurity platform for breach detection and data security.

BlgCloud sale post.

Cybersecurity breach graphic with SpyCloud branding and data leak visuals.

Screenshot of the most recent BlgCloud leak to date, posted on August 28.

A wild LeakBase has appeared!

The individual behind “Chucky” – the moniker used by the owner of the popular data breach forum LeakBase – was arrested by Russian authorities back in March, and LeakBase was subsequently seized. In late July, the LeakBase site popped back up, and Chucky’s old LeakBase-related Telegram channels were archived and migrated over to new channels.  The user administering the forum goes by chucky_arested on Telegram, and simply Admin on the forum site. While it’s unclear what this new administrator’s relationship is to Chucky, they do at least appear to have access to a copy of the backend database from the original LeakBase (something that was never leaked publicly after the site was taken down), as well as administrative control over Chucky’s old Telegram channels. This means that the new account likely has some affiliation with the original Chucky (or that they are literally the Russian authorities, although the fact that chucky_arested/Admin has released multiple unique breached datasets over the past month would suggest that it is likely not the Russian Ministry of Internal Affairs conducting a sting operation).
SpyCloud cybersecurity platform analyzing breach data and leak prevention.

Homepage of the revived LeakBase at leakbase[.]su. 

This revival of an old forum instead of creating a new one echoes the proliferation of multiple copycat BreachForums sites since the real BreachForums went down back in April 2025. Reviving an existing forum brings some cache in the form of name recognition, and it also brings an existing pool of users. In the wake of the BreachForums takedown, multiple actors used leaked versions of the old site’s backend and user base to make their own copycat forums. PwnForums, for example, used a leaked version of the BreachForums backend database to pre-populate content and users onto their forum, so users could log in to PwnForums with their old BreachForums login credentials.

Other research insights from SpyCloud Labs

On June 24, 2026, an international law enforcement coalition seized the infrastructure behind StealC, one of the more widely used information stealers of the past three years. 

Attackers are finding new ways to make MFA irrelevant, and device code phishing is their latest weapon. This adversary-in-the-middle (AiTM) technique exploits the legitimate OAuth 2.0 Device Authorization Grant flow, tricking users into entering an attacker-generated code that issues active session tokens directly to the attacker’s device. Here’s what you need to know.

Recaptured data numbers for August 2026

August monthly total

Total New Recaptured Data Records for August:
2,340,072,685

New third-party breach data this month

Third-Party Breaches Parsed and Ingested:
3,534
New Data Records from Third-Party Breaches:
1,657,278,249

New recaptured phished data this month

New Phished Data Records:
41,933,496

New infostealer malware data this month

Stealer Logs Parsed and Ingested:
4,532,162
New Data Records from Stealer Infections:
148,025,735
New Stolen Cookie Records:
533,646,192

Discover what cybercriminals know about your business and your customers – and how to prevent targeted attacks with SpyCloud.

Keep reading

Remus Infostealer cybersecurity logo with binary code background.
Remus: A New Infostealer Hunting Wallets, Passwords, and AI Credentials
SpyCloud Labs data shows StealC fell 90% before the June 24 Operation Endgame takedown. See what our post-takedown analysis reveals.
Cybercrime update graphic showing ShinyHunters and criminal forums trends.
The SECTION9 Hoax, Forum Wars, & Phishing Kits Built to Beat MFA
Read on for the latest from the criminal underground, including details of the Klue breach, Operation Endgame’s latest malware disruption, and trends in AI cybercrime slop.
Analysis of Stealc malware takedown by SpyCloud for cybersecurity.
Peers Held, StealC Didn’t: Analyzing the June 24 Takedown in SpyCloud’s Data
SpyCloud Labs data shows StealC fell 90% before the June 24 Operation Endgame takedown. See what our post-takedown analysis reveals.

Check Your Company's Exposure

See your real-time exposure details powered by SpyCloud.