~/f4n6 $ grep -r "Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire" ./investigations/ --include="*.md"
Bluekit

Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire

Jeff Davies 26 Jun 2026 17 min read

Bluekit and the AI Impersonators — FindEvil

Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire

26 June 2026 · FindEvil — dAIffed / Adverse Trace · Case Refs: BLUEKIT-PHA-2026-001, AI-IMPERSONATION-2026-001 · Confidence: HIGH

TL;DR

What started as a phishing kit hunt turned into the discovery of a sprawling web empire operated by a Singapore-registered company. Using 15 URLScan screenshots analyzed via local vision LLM, 5 IP pivots, and Certificate Transparency data, we identified 69+ domains across two distinct threats.

  • 5 Bluekit phishing kit domains RED
  • 17+ AI brand impersonation domains (9 screenshot-verified, 8 infrastructure-confirmed) HIGH
  • 1 credential harvesting domain (log-in-account.com, phishing since 2021) RED
  • 5 generic AI/tool domains on shared infra (NOT impersonations) MEDIUM
  • 38+ game domains by the same company AMBER
  • 1 mobile app with 1M+ downloads and documented user fraud CONFIRMED
  • 1 operator: AppStation Studio PTE. LTD, Singapore

This is not 18 impersonation domains. It is a mixed portfolio: some are clear brand impersonations, some are generic tools, some are game clones, and one is a credential harvesting domain. All drive traffic to mobile apps with documented fraud. This article corrects our earlier over-claims with screenshot evidence and documents the follow-up investigation that expanded the scope from 56 to 69+ domains.

Part 1: Hunting Bluekit

The Target

Varonis Threat Labs published research on Bluekit in April 2026, describing an AI-powered all-in-one phishing kit with 40+ phishing templates (Outlook, Gmail, iCloud, GitHub, Ledger, etc.), browser-in-the-middle (BitM) attack methodology using rrweb, AI Assistant with multiple model options, Telegram exfiltration, automated domain registration, and session hijacking.

The Hunt

We ran the phishing tracker pipeline against the Bluekit source articles, extracting 52 markers and generating 98 search queries. The pipeline returned 263 candidates. Of 263, 252 were false positives. But five domains stood out.

The Infrastructure

DomainTitleIPFirst CertTLP
bluekit.su"your phishing kit"188.114.96.12 (CF)2026-03-25RED
bluekit.cc"your phishing kit"172.67.180.211 (CF)2026-03-23RED
bluekit.pk"your best kit"188.114.96.3 (CF)UnknownRED
bluekit.ws"your phishing kit"104.21.79.189 (CF)2026-04-28RED
bluekit.la"bluekit"2a06:98c1:3121::3 (CF)No CTRED

All are Cloudflare-fronted. The two-day gap between .cc (March 23) and .su (March 25) is the strongest evidence of a single operator registering domains in quick succession.

What We Did not Find

Despite extensive searching, we found zero victim-side phishing pages. The five domains are the kit's own landing/admin infrastructure.

MITRE ATT&CK Mapping

Technique IDNameTacticConfidence
T11812FA TheftCredential AccessHIGH
T1550Use Alternate Auth MaterialDefense EvasionMEDIUM
T1071C2 over webC2LOW
T1584Gather Victim Host InfoReconnaissanceMEDIUM

Part 2: The AI Impersonation Operation

The Accidental Discovery

During candidate triage, deepseek.net and chat-gpt.org surfaced on the same Hetzner IP (65.108.76.151, PTR: mail.chat-gpt.org). IP pivots revealed 9 domains on that IP, 3 on AlexHost MD, and 36+ game domains on a third Hetzner IP. By the end, we had 56 domains across four hosting providers.

A follow-up investigation — pivoting on the old AppStation server (176.123.6.10, host.gptserver.com), the AdSense publisher ID, and the credential harvesting domain log-in-account.com — revealed 13 additional domains, bringing the total to 69+. This approaches the "70+ web apps" claimed on the AppStation Studio website.

Screenshot Evidence

We downloaded 15 URLScan screenshots and analyzed each using a local vision LLM (Qwen3.6-MoE on llama.cpp). Here are the honest results:

Tier 1: Confirmed Brand Impersonations

HIGH screenshot verified

DomainImpersonatesScreenshot EvidenceUUID
deepseek.netDeepSeekBlue whale logo, App Store button. Finnish cookie consent.019efb08
deep-seek.comDeepSeekLogo in header + mock chat. French cookie consent.019f013a
deep-seek.aiDeepSeekLogo top left. German cookie consent.019ed5b1
chatgbt.orgChatGPT (GBT)Green logo, App Store + Google Play, dating ads.019daa05
chatgot.orgChatGPT (GOT)OpenAI knot logo, App Store + Google Play.019daa05
chat-gpt.org / chatai.orgChatGPTChatAI branding, GPT-5 promo, Yandex Metrica.019d82fb
removebg.netremove.bg"Remove BG - Background Remover". Finnish.019d77ce
humanize.orgHumanizeAI.comBrain-icon logo. Finnish cookie consent.019dbeb1
drive.log-in-account.comChatGPTLogo, nav bar, App Store buttons. French.019e4057

9 confirmed brand impersonations with screenshot evidence. CONFIRMED

Follow-up: 8 Additional AI Impersonation Domains

HIGH same infrastructure — confirmed via IP pivot on old server (176.123.6.10, host.gptserver.com)

DomainImpersonatesTitleServer
chatgpt5.orgChatGPT-5"Chat GPT-5 - Free ChatGPT 5"176.123.6.10
chatgpt4.orgChatGPT-4"Chat GPT 4 - ChatGPT Free"176.123.6.10
chatgtp.orgChatGPT (GTP)"ChatGTP - Chat GTP Free"176.123.6.10
chatgptgratis.comChatGPT (Spanish)"Chat GPT Gratis - ChatGPT en Español"176.123.6.10
gpt.chatChatGPT-5"ChatGPT-5 — Free Advanced AI Chat"176.123.6.10
manus.orgManus AI"Manus AI – Free AI Chat Online"176.123.6.10
chat-gpt.orgChatGPT"ChatGPT Online Free — Chat with GPT-5"176.123.6.10 → 176.125.242.237
ai-chat.orgChatGPT"AI Chat - ChatGPT & Image Generator"65.108.78.181 (since May 2023)

Credential Harvesting: log-in-account.com

log-in-account.com — domain name designed for credential harvesting. Historical phishing subdomains: login.bolklchaln.com.log-in-account.com on DDOS-GUARD RU (2021). Now Cloudflare-fronted with drive.log-in-account.com serving ChatGPT impersonation. Confirmed AppStation-linked via Yandex Metrica ID 108435860, App Store/Google Play links, chatgpt.org resource loading, and Google AdSense pub ID ca-pub-1851068468056357.

New AI Tool: gptimage.com

gptimage.com — GPT Image impersonation ("GPT Image - AI Image Generator Online"). Vite/React SPA, Google Analytics ID G-MBCNYWT2MG. Linked from drive.log-in-account.com. Same design language as other AppStation sites.

View screenshots — Tier 1 confirmed impersonations

deepseek.net

deepseek.net — impersonates DeepSeek
deepseek.net — impersonates DeepSeek

deep-seek.com

deep-seek.com — impersonates DeepSeek
deep-seek.com — impersonates DeepSeek

deep-seek.ai

deep-seek.ai — impersonates DeepSeek
deep-seek.ai — impersonates DeepSeek

chatgbt.org

chatgbt.org — impersonates ChatGPT (GBT)
chatgbt.org — impersonates ChatGPT (GBT)

chatgot.org

chatgot.org — impersonates ChatGPT (GOT)
chatgot.org — impersonates ChatGPT (GOT)

chat-gpt.org / chatai.org

chat-gpt.org / chatai.org — impersonates ChatGPT
chat-gpt.org / chatai.org — impersonates ChatGPT

removebg.net

removebg.net — impersonates remove.bg
removebg.net — impersonates remove.bg

humanize.org

humanize.org — impersonates HumanizeAI.com
humanize.org — impersonates HumanizeAI.com

drive.log-in-account.com

drive.log-in-account.com — impersonates ChatGPT
drive.log-in-account.com — impersonates ChatGPT

Tier 2: Generic Tools on Shared Infrastructure

MEDIUM NOT impersonations

DomainTitleScreenshot EvidenceUUID
upscale.orgUpscale ImageBlue arrow logo, drag-and-drop. MAY mimic Upscale.media.019df035
spinwheel.orgSpin the WheelCustomizable wheel. NOT an impersonation.019de777
aigenerator.orgAI GeneratorDark theme, text-to-image. NOT a specific brand.019d985f
aidetector.aiAI DetectorText analysis tool. Not a specific brand impersonation.019bbcce
aichat.orgAI ChatAI model aggregator. No URLScan screenshot.NONE

5 domains that are NOT impersonations but are on shared infrastructure. NOT IMPS

View screenshots — Tier 2 generic tools

upscale.org

upscale.org — Upscale Image
upscale.org — Upscale Image

spinwheel.org

spinwheel.org — Spin the Wheel
spinwheel.org — Spin the Wheel

aigenerator.org

aigenerator.org — AI Generator
aigenerator.org — AI Generator

aidetector.ai

aidetector.ai — AI Detector
aidetector.ai — AI Detector

Tier 3: Operator Infrastructure

DomainWhat it isEvidence
appstation.studioAppStation Studio corporate site"[app]station" logo, "We develop" headline.
softparade.netPossible predecessor brandOn same IP. URLScan back to 2021. Currently 522.
ai-chat.aiEmail domain onlyNo website, no screenshot.
View screenshot — AppStation Studio operator site

appstation.studio

appstation.studio — AppStation Studio corporate website
appstation.studio — AppStation Studio corporate website

Tier 4: Credential Harvesting Infrastructure

log-in-account.com — credential harvesting domain. Subdomain drive.log-in-account.com serves ChatGPT interface. Confirmed AppStation-linked. Historical phishing subdomains dating to 2021 (DDOS-GUARD RU). See follow-up section above.

The Game Empire

The third Hetzner IP (65.108.78.181) hosts 38+ game domains. These are NOT impersonations — they are game clones. But they are operated by the same company and drive traffic to the same mobile apps.

wordly.org · globle.org · flagle.org · georiddle.org · geoguesser.io · worldlegame.io · closeword.org · numberle.org · crazygames.org · flappybird.gg · flappybird.run · blockblast.game · watermelongame.com · retrobowl.org · mahjong.gg · image-generator.com · spellbee.org · infinite-craft.com · infinitecraft.net · connect.game · squares.org · combinations.org · phrazle.gg · wordwaffle.org · crosswordle.org · strands.game · dordlewordle.com · quordly.com · octordly.com · sedecordlegame.org · weavergame.org · wordsearch.io · unwordle.org · sudoku-online.com · 2048.gg · solitaire.online · snowrider.com · driftboss.org

38+ game domains linked from wordly.org's own page and discovered via IP pivots.

The Mobile App & Fraud

  • App name: "AI Chat: AI Chatbot Assistant"
  • Package: com.appstation.chatgpt
  • iOS ID: id6468878395
  • Downloads: 1,000,000+ · Reviews: 28,900 (4.5-star)
  • Developer: APPSTATION STUDIO PTE. LTD, 68 Circular Road #02-01, Singapore 049422

The Fraud

David Orr (March 2023): "I just got scammed by this app! It asked me to enter my credit card number to 'verify' my identity... my bank's fraud division blocked the transaction — which was trying to charge me $39.99." (292 helpful)

Lyn P (February 2024): "My bank account has had successive amounts ($28 each time) deducted on several dates, all charged by ChatGPT. Had to close both my card + bank accounts." (92 helpful)

The Russian Connection

chat-gpt.org loads Yandex Metrica: mc.yandex.ru/watch/108435860

Infrastructure Summary

IPHostingPTRDomainsPurpose
65.108.76.151Hetzner DEmail.chat-gpt.org9AI impersonation
65.108.78.181Hetzner DEstatic.181.78...38+Game sites + ai-chat.org
176.123.6.10AlexHost MDhost.gptserver.com8+AI impersonation (old server, Aug 2024–Apr 2026)
176.125.242.237AlexHost MDserver.chatgpt.org3+ChatGPT sites (current server)
205.196.81.104BIZNESSHOSTING USs1d71a3de...1deep-seek.ai
135.181.58.97Hetzner DEstatic.97.58...2Operator
CloudflareVariousN/A3+deep-seek.com, log-in-account.com, flappybird.run

Historical Infrastructure Migration

The operation migrated from 176.123.6.10 (host.gptserver.com, nginx/1.20.2) to 176.125.242.237 (server.chatgpt.org, nginx/1.22.1) in April 2026. Both on AlexHost (Moldova).

Timeline

DateEvent
2021-05-26login.bolklchaln.com.log-in-account.com on DDOS-GUARD RU — earliest log-in-account.com phishing
2021-09-07softparade.net first URLScan scan
2023-02-14First CT log for chat-gpt.org
2023-03-14First CT log for deepseek.net
2023-03First fraud report (David Orr, $39.99)
2023-05ai-chat.org first scan on games server (65.108.78.181)
2024-02-21image-generator.com first URLScan
2024-06-16log-in-account.com parked on TWENTYI GB — "This site is brand new"
2024-08chatgpt.org first scan on AlexHost MD (176.123.6.10)
2025-04-10removebg.net launched
2025-04-20chatgot.org + chatgbt.org launched
2025-05-12deepseek.net + chat-gpt.org first scans
2024-02Second fraud report (Lyn P, $28 repeated)
2026-04-06chatgpt.org migrated to new AlexHost server (176.125.242.237)
2026-04-12chat-gpt.org rebranded to ChatAI.org
2026-04-20chatgpt5.org, chatgpt4.org, chatgtp.org, chatgptgratis.com, gpt.chat all scanned same day
2026-05-19drive.log-in-account.com appears — ChatGPT impersonation on Cloudflare
2026-06-17chatai.org first URLScan scan
2026-06-26Investigation completed
2026-06-26Follow-up: 13 new domains discovered, total 69+

Honesty Correction

What we got wrong initially: Called all 18 domains "impersonations" — actually only 9 are confirmed. Over-claimed on generic tools. No screenshots initially. Now fixed. The follow-up investigation added 8 more AI impersonations confirmed via infrastructure attribution (total: 17).

What We Got Wrong

  1. Called all 18 domains "impersonations" — only 9 are confirmed. 5 are generic tools, 3 are operator, 1 is credential harvesting.
  2. Claimed 18 domains — actually 69+ across 4 IPs (17 AI + 38 games + 5 operator + 9 adjacent/credential harvesting).
  3. No screenshots — now 15 screenshots analyzed via local vision LLM.
  4. Over-claimed on generic tools — spinwheel.org, aigenerator.org, aidetector.ai are NOT impersonations.
  5. Missed the old server — follow-up investigation discovered the old AlexHost server (176.123.6.10) hosting 8+ additional AI impersonation domains.

What We Got Right

  1. Operator identity — AppStation Studio PTE. LTD, Singapore.
  2. Infrastructure pattern — 4 hosting providers.
  3. Mobile app fraud — documented user reviews.
  4. Russian analytics — Yandex Metrica ID 108435860.
  5. Cross-linking — wordly.org links to com.appstation.wordly.

IOCs

Bluekit Phishing Kit

IndicatorTypeConfidenceContext
bluekit.sudomainHIGHKit landing page
bluekit.ccdomainHIGHKit landing page
bluekit.pkdomainHIGHKit landing page
bluekit.wsdomainHIGHKit landing page
bluekit.ladomainHIGHKit landing page

AI Impersonation — Confirmed (screenshot-verified)

IndicatorTypeConfidenceContext
deepseek.netdomainHIGHDeepSeek impersonation — blue whale logo. App Store button.
deep-seek.comdomainHIGHDeepSeek impersonation — logo in header and chat
deep-seek.aidomainHIGHDeepSeek impersonation — logo confirmed
chatgbt.orgdomainHIGHChatGPT typosquat — green logo, App Store buttons
chatgot.orgdomainHIGHChatGPT typosquat — OpenAI knot logo
chat-gpt.orgdomainHIGHChatGPT impersonation — rebranded to ChatAI.org
chatai.orgdomainHIGHChatAI rebrand of chat-gpt.org
chatgpt.orgdomainHIGHChatGPT impersonation (no hyphen)
removebg.netdomainHIGHremove.bg impersonation — confirmed via screenshot
humanize.orgdomainHIGHHumanizeAI.com impersonation — brain icon logo
drive.log-in-account.comdomainHIGHChatGPT interface — logo, nav bar, App Store
65.108.76.151ipHIGHHetzner DE, PTR: mail.chat-gpt.org
176.125.242.237ipMEDIUMAlexHost MD, PTR: server.chatgpt.org
205.196.81.104ipMEDIUMBIZNESSHOSTING US — deep-seek.ai
appstation.studiodomainHIGHOperator — AppStation Studio PTE. LTD

Follow-up Discoveries (same infrastructure, confirmed via IP pivot)

IndicatorTypeConfidenceContext
chatgpt5.orgdomainHIGHChatGPT-5 impersonation on old AlexHost server (176.123.6.10)
chatgpt4.orgdomainHIGHChatGPT-4 impersonation on old AlexHost server
chatgtp.orgdomainHIGHChatGPT typosquat (GPT→GTP)
chatgptgratis.comdomainHIGHChatGPT Spanish-language impersonation
gpt.chatdomainHIGHChatGPT-5 impersonation — premium domain
manus.orgdomainHIGHManus AI impersonation
ai-chat.orgdomainHIGHAI Chat impersonation on games server since May 2023
log-in-account.comdomainHIGHCredential harvesting domain — phishing since 2021. drive.log-in-account.com confirmed AppStation-linked
gptimage.comdomainMEDIUMGPT Image impersonation — linked from drive.log-in-account.com
176.123.6.10ipMEDIUMAlexHost MD, PTR: host.gptserver.com — old server
spellbee.orgdomainHIGHSpelling Bee game on old AlexHost server
infinite-craft.comdomainHIGHInfinite Craft game on old AlexHost server

Generic Tools (NOT impersonations)

IndicatorConfidenceContext
upscale.orgMEDIUMGeneric AI upscaler
spinwheel.orgLOWGeneric wheel tool
aigenerator.orgLOWGeneric AI generator
aidetector.aiLOWGeneric AI detector
aichat.orgMEDIUMAI chat aggregator

Possibly Related

IndicatorConfidenceContext
imagegpt.orgMEDIUMLinked from deep-seek.com
picai.comMEDIUMLinked from deep-seek.ai
softparade.netMEDIUMOn appstation.studio IP

Recommendations

For Defenders

  1. Block 17+ AI impersonation domains (including 8 follow-up discoveries) at DNS filter/firewall
  2. Block 4 infrastructure IPs at network egress (65.108.76.151, 176.123.6.10, 176.125.242.237, 205.196.81.104)
  3. Block Bluekit domains (bluekit.su, .cc, .pk, .ws, .la)
  4. Block log-in-account.com and all subdomains — credential harvesting domain
  5. Add Yandex Metrica ID 108435860 to proxy block list
  6. Add AdSense pub ID ca-pub-1851068468056357 to proxy block list
  7. Monitor mobile app (com.appstation.chatgpt) via MDM
  8. Educate users about "free AI chat" websites

For Platform Trust Teams

  1. Google Play / Apple: App has documented user fraud. Review in-app purchases.
  2. Cloudflare: Bluekit domains use your infrastructure.
  3. Hetzner: IPs 65.108.76.151 and 65.108.78.181 host 47+ domains.
  4. AlexHost: IPs 176.123.6.10 and 176.125.242.237 host ChatGPT impersonation domains.

For Threat Hunters

  1. Monitor URLScan for page.title:"bluekit - your phishing kit"
  2. Monitor CT for new bluekit.* certs
  3. Watch Yandex Metrica ID 108435860
  4. Pivot on PTR mail.chat-gpt.org
  5. Check passive DNS for pre-Cloudflare Bluekit IPs

Methodology

Tools Used

  • Phishing Tracker Pipeline: Source ingestion, marker extraction, queries
  • URLScan: Live queries, IP pivots, screenshot retrieval
  • Certificate Transparency (crt.sh): TLS certificate history
  • WebFetch: Direct page retrieval
  • Local Vision LLM: Qwen3.6-MoE on llama.cpp for screenshot analysis
  • Tesseract OCR: Cross-validation of screenshot content
  • Intel Store: Observable registration, relationship mapping

What Worked

  1. URLScan title queries — highest yield
  2. IP pivoting — critical for full domain cluster
  3. Certificate Transparency — launch timeline
  4. Google Play listing — connected 69+ domains to named entity
  5. Local vision LLM — screenshot analysis without external API
  6. Historical IP pivoting — old server (176.123.6.10) revealed 8+ new domains
  7. AdSense publisher ID — linked drive.log-in-account.com to AppStation

What Did not Work

  1. kit_wording evidence type — 98% false positives
  2. IP pivoting for Bluekit — all Cloudflare anycast
  3. No rrweb/WebSocket fingerprints found
  4. crt.sh unreliable — 502 errors on multiple domains

Acknowledgements

  • Varonis Threat Labs — original Bluekit research
  • URLScan.io — scanning infrastructure
  • crt.sh — Certificate Transparency data
  • Qwen3.6-MoE vision model on local llama.cpp server
Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies