Browser-in-the-Middle phishing has evolved. Bluekit uses a session replay library (rrweb) to stream a live, interactive login page from the attacker's browser to the victim's. It looks and behaves exactly like the real thing — because it is. New research from our team: https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat #phishing #PhishingKits