Bluekit and the AI Impersonators: A Phishing Kit Hunt That Uncovered a Fraud Empire
Contents
TL;DR
What started as a phishing kit hunt turned into the discovery of a sprawling web empire operated by a Singapore-registered company. Using 15 URLScan screenshots analyzed via local vision LLM, 5 IP pivots, and Certificate Transparency data, we identified 69+ domains across two distinct threats.
- 5 Bluekit phishing kit domains RED
- 17+ AI brand impersonation domains (9 screenshot-verified, 8 infrastructure-confirmed) HIGH
- 1 credential harvesting domain (log-in-account.com, phishing since 2021) RED
- 5 generic AI/tool domains on shared infra (NOT impersonations) MEDIUM
- 38+ game domains by the same company AMBER
- 1 mobile app with 1M+ downloads and documented user fraud CONFIRMED
- 1 operator: AppStation Studio PTE. LTD, Singapore
This is not 18 impersonation domains. It is a mixed portfolio: some are clear brand impersonations, some are generic tools, some are game clones, and one is a credential harvesting domain. All drive traffic to mobile apps with documented fraud. This article corrects our earlier over-claims with screenshot evidence and documents the follow-up investigation that expanded the scope from 56 to 69+ domains.
Part 1: Hunting Bluekit
The Target
Varonis Threat Labs published research on Bluekit in April 2026, describing an AI-powered all-in-one phishing kit with 40+ phishing templates (Outlook, Gmail, iCloud, GitHub, Ledger, etc.), browser-in-the-middle (BitM) attack methodology using rrweb, AI Assistant with multiple model options, Telegram exfiltration, automated domain registration, and session hijacking.
The Hunt
We ran the phishing tracker pipeline against the Bluekit source articles, extracting 52 markers and generating 98 search queries. The pipeline returned 263 candidates. Of 263, 252 were false positives. But five domains stood out.
The Infrastructure
| Domain | Title | IP | First Cert | TLP |
|---|---|---|---|---|
bluekit.su | "your phishing kit" | 188.114.96.12 (CF) | 2026-03-25 | RED |
bluekit.cc | "your phishing kit" | 172.67.180.211 (CF) | 2026-03-23 | RED |
bluekit.pk | "your best kit" | 188.114.96.3 (CF) | Unknown | RED |
bluekit.ws | "your phishing kit" | 104.21.79.189 (CF) | 2026-04-28 | RED |
bluekit.la | "bluekit" | 2a06:98c1:3121::3 (CF) | No CT | RED |
All are Cloudflare-fronted. The two-day gap between .cc (March 23) and .su (March 25) is the strongest evidence of a single operator registering domains in quick succession.
What We Did not Find
Despite extensive searching, we found zero victim-side phishing pages. The five domains are the kit's own landing/admin infrastructure.
MITRE ATT&CK Mapping
| Technique ID | Name | Tactic | Confidence |
|---|---|---|---|
T1181 | 2FA Theft | Credential Access | HIGH |
T1550 | Use Alternate Auth Material | Defense Evasion | MEDIUM |
T1071 | C2 over web | C2 | LOW |
T1584 | Gather Victim Host Info | Reconnaissance | MEDIUM |
Part 2: The AI Impersonation Operation
The Accidental Discovery
During candidate triage, deepseek.net and chat-gpt.org surfaced on the same Hetzner IP (65.108.76.151, PTR: mail.chat-gpt.org). IP pivots revealed 9 domains on that IP, 3 on AlexHost MD, and 36+ game domains on a third Hetzner IP. By the end, we had 56 domains across four hosting providers.
A follow-up investigation — pivoting on the old AppStation server (176.123.6.10, host.gptserver.com), the AdSense publisher ID, and the credential harvesting domain log-in-account.com — revealed 13 additional domains, bringing the total to 69+. This approaches the "70+ web apps" claimed on the AppStation Studio website.
Screenshot Evidence
We downloaded 15 URLScan screenshots and analyzed each using a local vision LLM (Qwen3.6-MoE on llama.cpp). Here are the honest results:
Tier 1: Confirmed Brand Impersonations
HIGH screenshot verified
| Domain | Impersonates | Screenshot Evidence | UUID |
|---|---|---|---|
deepseek.net | DeepSeek | Blue whale logo, App Store button. Finnish cookie consent. | 019efb08 |
deep-seek.com | DeepSeek | Logo in header + mock chat. French cookie consent. | 019f013a |
deep-seek.ai | DeepSeek | Logo top left. German cookie consent. | 019ed5b1 |
chatgbt.org | ChatGPT (GBT) | Green logo, App Store + Google Play, dating ads. | 019daa05 |
chatgot.org | ChatGPT (GOT) | OpenAI knot logo, App Store + Google Play. | 019daa05 |
chat-gpt.org / chatai.org | ChatGPT | ChatAI branding, GPT-5 promo, Yandex Metrica. | 019d82fb |
removebg.net | remove.bg | "Remove BG - Background Remover". Finnish. | 019d77ce |
humanize.org | HumanizeAI.com | Brain-icon logo. Finnish cookie consent. | 019dbeb1 |
drive.log-in-account.com | ChatGPT | Logo, nav bar, App Store buttons. French. | 019e4057 |
9 confirmed brand impersonations with screenshot evidence. CONFIRMED
Follow-up: 8 Additional AI Impersonation Domains
HIGH same infrastructure — confirmed via IP pivot on old server (176.123.6.10, host.gptserver.com)
| Domain | Impersonates | Title | Server |
|---|---|---|---|
chatgpt5.org | ChatGPT-5 | "Chat GPT-5 - Free ChatGPT 5" | 176.123.6.10 |
chatgpt4.org | ChatGPT-4 | "Chat GPT 4 - ChatGPT Free" | 176.123.6.10 |
chatgtp.org | ChatGPT (GTP) | "ChatGTP - Chat GTP Free" | 176.123.6.10 |
chatgptgratis.com | ChatGPT (Spanish) | "Chat GPT Gratis - ChatGPT en Español" | 176.123.6.10 |
gpt.chat | ChatGPT-5 | "ChatGPT-5 — Free Advanced AI Chat" | 176.123.6.10 |
manus.org | Manus AI | "Manus AI – Free AI Chat Online" | 176.123.6.10 |
chat-gpt.org | ChatGPT | "ChatGPT Online Free — Chat with GPT-5" | 176.123.6.10 → 176.125.242.237 |
ai-chat.org | ChatGPT | "AI Chat - ChatGPT & Image Generator" | 65.108.78.181 (since May 2023) |
Credential Harvesting: log-in-account.com
log-in-account.com — domain name designed for credential harvesting. Historical phishing subdomains: login.bolklchaln.com.log-in-account.com on DDOS-GUARD RU (2021). Now Cloudflare-fronted with drive.log-in-account.com serving ChatGPT impersonation. Confirmed AppStation-linked via Yandex Metrica ID 108435860, App Store/Google Play links, chatgpt.org resource loading, and Google AdSense pub ID ca-pub-1851068468056357.
New AI Tool: gptimage.com
gptimage.com — GPT Image impersonation ("GPT Image - AI Image Generator Online"). Vite/React SPA, Google Analytics ID G-MBCNYWT2MG. Linked from drive.log-in-account.com. Same design language as other AppStation sites.
View screenshots — Tier 1 confirmed impersonations
deepseek.net
deep-seek.com
deep-seek.ai
chatgbt.org
chatgot.org
chat-gpt.org / chatai.org
removebg.net
humanize.org
drive.log-in-account.com
Tier 2: Generic Tools on Shared Infrastructure
MEDIUM NOT impersonations
| Domain | Title | Screenshot Evidence | UUID |
|---|---|---|---|
upscale.org | Upscale Image | Blue arrow logo, drag-and-drop. MAY mimic Upscale.media. | 019df035 |
spinwheel.org | Spin the Wheel | Customizable wheel. NOT an impersonation. | 019de777 |
aigenerator.org | AI Generator | Dark theme, text-to-image. NOT a specific brand. | 019d985f |
aidetector.ai | AI Detector | Text analysis tool. Not a specific brand impersonation. | 019bbcce |
aichat.org | AI Chat | AI model aggregator. No URLScan screenshot. | NONE |
5 domains that are NOT impersonations but are on shared infrastructure. NOT IMPS
View screenshots — Tier 2 generic tools
upscale.org
spinwheel.org
aigenerator.org
aidetector.ai
Tier 3: Operator Infrastructure
| Domain | What it is | Evidence |
|---|---|---|
appstation.studio | AppStation Studio corporate site | "[app]station" logo, "We develop" headline. |
softparade.net | Possible predecessor brand | On same IP. URLScan back to 2021. Currently 522. |
ai-chat.ai | Email domain only | No website, no screenshot. |
View screenshot — AppStation Studio operator site
appstation.studio
Tier 4: Credential Harvesting Infrastructure
log-in-account.com — credential harvesting domain. Subdomain drive.log-in-account.com serves ChatGPT interface. Confirmed AppStation-linked. Historical phishing subdomains dating to 2021 (DDOS-GUARD RU). See follow-up section above.
The Game Empire
The third Hetzner IP (65.108.78.181) hosts 38+ game domains. These are NOT impersonations — they are game clones. But they are operated by the same company and drive traffic to the same mobile apps.
wordly.org · globle.org · flagle.org · georiddle.org · geoguesser.io · worldlegame.io · closeword.org · numberle.org · crazygames.org · flappybird.gg · flappybird.run · blockblast.game · watermelongame.com · retrobowl.org · mahjong.gg · image-generator.com · spellbee.org · infinite-craft.com · infinitecraft.net · connect.game · squares.org · combinations.org · phrazle.gg · wordwaffle.org · crosswordle.org · strands.game · dordlewordle.com · quordly.com · octordly.com · sedecordlegame.org · weavergame.org · wordsearch.io · unwordle.org · sudoku-online.com · 2048.gg · solitaire.online · snowrider.com · driftboss.org
38+ game domains linked from wordly.org's own page and discovered via IP pivots.
The Mobile App & Fraud
- App name: "AI Chat: AI Chatbot Assistant"
- Package:
com.appstation.chatgpt - iOS ID:
id6468878395 - Downloads: 1,000,000+ · Reviews: 28,900 (4.5-star)
- Developer: APPSTATION STUDIO PTE. LTD, 68 Circular Road #02-01, Singapore 049422
The Fraud
David Orr (March 2023): "I just got scammed by this app! It asked me to enter my credit card number to 'verify' my identity... my bank's fraud division blocked the transaction — which was trying to charge me $39.99." (292 helpful)
Lyn P (February 2024): "My bank account has had successive amounts ($28 each time) deducted on several dates, all charged by ChatGPT. Had to close both my card + bank accounts." (92 helpful)
The Russian Connection
chat-gpt.org loads Yandex Metrica: mc.yandex.ru/watch/108435860
Infrastructure Summary
| IP | Hosting | PTR | Domains | Purpose |
|---|---|---|---|---|
65.108.76.151 | Hetzner DE | mail.chat-gpt.org | 9 | AI impersonation |
65.108.78.181 | Hetzner DE | static.181.78... | 38+ | Game sites + ai-chat.org |
176.123.6.10 | AlexHost MD | host.gptserver.com | 8+ | AI impersonation (old server, Aug 2024–Apr 2026) |
176.125.242.237 | AlexHost MD | server.chatgpt.org | 3+ | ChatGPT sites (current server) |
205.196.81.104 | BIZNESSHOSTING US | s1d71a3de... | 1 | deep-seek.ai |
135.181.58.97 | Hetzner DE | static.97.58... | 2 | Operator |
| Cloudflare | Various | N/A | 3+ | deep-seek.com, log-in-account.com, flappybird.run |
Historical Infrastructure Migration
The operation migrated from 176.123.6.10 (host.gptserver.com, nginx/1.20.2) to 176.125.242.237 (server.chatgpt.org, nginx/1.22.1) in April 2026. Both on AlexHost (Moldova).
Timeline
| Date | Event |
|---|---|
2021-05-26 | login.bolklchaln.com.log-in-account.com on DDOS-GUARD RU — earliest log-in-account.com phishing |
2021-09-07 | softparade.net first URLScan scan |
2023-02-14 | First CT log for chat-gpt.org |
2023-03-14 | First CT log for deepseek.net |
2023-03 | First fraud report (David Orr, $39.99) |
2023-05 | ai-chat.org first scan on games server (65.108.78.181) |
2024-02-21 | image-generator.com first URLScan |
2024-06-16 | log-in-account.com parked on TWENTYI GB — "This site is brand new" |
2024-08 | chatgpt.org first scan on AlexHost MD (176.123.6.10) |
2025-04-10 | removebg.net launched |
2025-04-20 | chatgot.org + chatgbt.org launched |
2025-05-12 | deepseek.net + chat-gpt.org first scans |
2024-02 | Second fraud report (Lyn P, $28 repeated) |
2026-04-06 | chatgpt.org migrated to new AlexHost server (176.125.242.237) |
2026-04-12 | chat-gpt.org rebranded to ChatAI.org |
2026-04-20 | chatgpt5.org, chatgpt4.org, chatgtp.org, chatgptgratis.com, gpt.chat all scanned same day |
2026-05-19 | drive.log-in-account.com appears — ChatGPT impersonation on Cloudflare |
2026-06-17 | chatai.org first URLScan scan |
2026-06-26 | Investigation completed |
2026-06-26 | Follow-up: 13 new domains discovered, total 69+ |
Honesty Correction
What we got wrong initially: Called all 18 domains "impersonations" — actually only 9 are confirmed. Over-claimed on generic tools. No screenshots initially. Now fixed. The follow-up investigation added 8 more AI impersonations confirmed via infrastructure attribution (total: 17).
What We Got Wrong
- Called all 18 domains "impersonations" — only 9 are confirmed. 5 are generic tools, 3 are operator, 1 is credential harvesting.
- Claimed 18 domains — actually 69+ across 4 IPs (17 AI + 38 games + 5 operator + 9 adjacent/credential harvesting).
- No screenshots — now 15 screenshots analyzed via local vision LLM.
- Over-claimed on generic tools — spinwheel.org, aigenerator.org, aidetector.ai are NOT impersonations.
- Missed the old server — follow-up investigation discovered the old AlexHost server (176.123.6.10) hosting 8+ additional AI impersonation domains.
What We Got Right
- Operator identity — AppStation Studio PTE. LTD, Singapore.
- Infrastructure pattern — 4 hosting providers.
- Mobile app fraud — documented user reviews.
- Russian analytics — Yandex Metrica ID 108435860.
- Cross-linking — wordly.org links to
com.appstation.wordly.
IOCs
Bluekit Phishing Kit
| Indicator | Type | Confidence | Context |
|---|---|---|---|
bluekit.su | domain | HIGH | Kit landing page |
bluekit.cc | domain | HIGH | Kit landing page |
bluekit.pk | domain | HIGH | Kit landing page |
bluekit.ws | domain | HIGH | Kit landing page |
bluekit.la | domain | HIGH | Kit landing page |
AI Impersonation — Confirmed (screenshot-verified)
| Indicator | Type | Confidence | Context |
|---|---|---|---|
deepseek.net | domain | HIGH | DeepSeek impersonation — blue whale logo. App Store button. |
deep-seek.com | domain | HIGH | DeepSeek impersonation — logo in header and chat |
deep-seek.ai | domain | HIGH | DeepSeek impersonation — logo confirmed |
chatgbt.org | domain | HIGH | ChatGPT typosquat — green logo, App Store buttons |
chatgot.org | domain | HIGH | ChatGPT typosquat — OpenAI knot logo |
chat-gpt.org | domain | HIGH | ChatGPT impersonation — rebranded to ChatAI.org |
chatai.org | domain | HIGH | ChatAI rebrand of chat-gpt.org |
chatgpt.org | domain | HIGH | ChatGPT impersonation (no hyphen) |
removebg.net | domain | HIGH | remove.bg impersonation — confirmed via screenshot |
humanize.org | domain | HIGH | HumanizeAI.com impersonation — brain icon logo |
drive.log-in-account.com | domain | HIGH | ChatGPT interface — logo, nav bar, App Store |
65.108.76.151 | ip | HIGH | Hetzner DE, PTR: mail.chat-gpt.org |
176.125.242.237 | ip | MEDIUM | AlexHost MD, PTR: server.chatgpt.org |
205.196.81.104 | ip | MEDIUM | BIZNESSHOSTING US — deep-seek.ai |
appstation.studio | domain | HIGH | Operator — AppStation Studio PTE. LTD |
Follow-up Discoveries (same infrastructure, confirmed via IP pivot)
| Indicator | Type | Confidence | Context |
|---|---|---|---|
chatgpt5.org | domain | HIGH | ChatGPT-5 impersonation on old AlexHost server (176.123.6.10) |
chatgpt4.org | domain | HIGH | ChatGPT-4 impersonation on old AlexHost server |
chatgtp.org | domain | HIGH | ChatGPT typosquat (GPT→GTP) |
chatgptgratis.com | domain | HIGH | ChatGPT Spanish-language impersonation |
gpt.chat | domain | HIGH | ChatGPT-5 impersonation — premium domain |
manus.org | domain | HIGH | Manus AI impersonation |
ai-chat.org | domain | HIGH | AI Chat impersonation on games server since May 2023 |
log-in-account.com | domain | HIGH | Credential harvesting domain — phishing since 2021. drive.log-in-account.com confirmed AppStation-linked |
gptimage.com | domain | MEDIUM | GPT Image impersonation — linked from drive.log-in-account.com |
176.123.6.10 | ip | MEDIUM | AlexHost MD, PTR: host.gptserver.com — old server |
spellbee.org | domain | HIGH | Spelling Bee game on old AlexHost server |
infinite-craft.com | domain | HIGH | Infinite Craft game on old AlexHost server |
Generic Tools (NOT impersonations)
| Indicator | Confidence | Context |
|---|---|---|
upscale.org | MEDIUM | Generic AI upscaler |
spinwheel.org | LOW | Generic wheel tool |
aigenerator.org | LOW | Generic AI generator |
aidetector.ai | LOW | Generic AI detector |
aichat.org | MEDIUM | AI chat aggregator |
Possibly Related
| Indicator | Confidence | Context |
|---|---|---|
imagegpt.org | MEDIUM | Linked from deep-seek.com |
picai.com | MEDIUM | Linked from deep-seek.ai |
softparade.net | MEDIUM | On appstation.studio IP |
Recommendations
For Defenders
- Block 17+ AI impersonation domains (including 8 follow-up discoveries) at DNS filter/firewall
- Block 4 infrastructure IPs at network egress (65.108.76.151, 176.123.6.10, 176.125.242.237, 205.196.81.104)
- Block Bluekit domains (bluekit.su, .cc, .pk, .ws, .la)
- Block log-in-account.com and all subdomains — credential harvesting domain
- Add Yandex Metrica ID 108435860 to proxy block list
- Add AdSense pub ID ca-pub-1851068468056357 to proxy block list
- Monitor mobile app (
com.appstation.chatgpt) via MDM - Educate users about "free AI chat" websites
For Platform Trust Teams
- Google Play / Apple: App has documented user fraud. Review in-app purchases.
- Cloudflare: Bluekit domains use your infrastructure.
- Hetzner: IPs 65.108.76.151 and 65.108.78.181 host 47+ domains.
- AlexHost: IPs 176.123.6.10 and 176.125.242.237 host ChatGPT impersonation domains.
For Threat Hunters
- Monitor URLScan for
page.title:"bluekit - your phishing kit" - Monitor CT for new
bluekit.*certs - Watch Yandex Metrica ID 108435860
- Pivot on PTR
mail.chat-gpt.org - Check passive DNS for pre-Cloudflare Bluekit IPs
Methodology
Tools Used
- Phishing Tracker Pipeline: Source ingestion, marker extraction, queries
- URLScan: Live queries, IP pivots, screenshot retrieval
- Certificate Transparency (crt.sh): TLS certificate history
- WebFetch: Direct page retrieval
- Local Vision LLM: Qwen3.6-MoE on llama.cpp for screenshot analysis
- Tesseract OCR: Cross-validation of screenshot content
- Intel Store: Observable registration, relationship mapping
What Worked
- URLScan title queries — highest yield
- IP pivoting — critical for full domain cluster
- Certificate Transparency — launch timeline
- Google Play listing — connected 69+ domains to named entity
- Local vision LLM — screenshot analysis without external API
- Historical IP pivoting — old server (176.123.6.10) revealed 8+ new domains
- AdSense publisher ID — linked drive.log-in-account.com to AppStation
What Did not Work
kit_wordingevidence type — 98% false positives- IP pivoting for Bluekit — all Cloudflare anycast
- No rrweb/WebSocket fingerprints found
- crt.sh unreliable — 502 errors on multiple domains
Acknowledgements
- Varonis Threat Labs — original Bluekit research
- URLScan.io — scanning infrastructure
- crt.sh — Certificate Transparency data
- Qwen3.6-MoE vision model on local llama.cpp server