Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Phishing - New Phishing Kit Starkiller Defeats Multi-Factor Authentication
Phishing Attacks Data Protection Identity & Access Management Latest News News & Analysis Threats and Vulnerabilities

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

Kirsten DoyleBy Kirsten DoyleFebruary 23, 20264 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing Kit Starkiller
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Abnormal has discovered a new phishing kit that allows bad actors to steal usernames and passwords with a toolkit that spoofs live login pages and bypasses multi-factor authentication (MFA) protections. 

Most phishing kits depend on static HTML clones of login pages, which, while effective, are inherently fragile. Even a small interface update from the brand being impersonated can instantly reveal the deception. 

“A new framework called Starkiller (not to be confused with the legitimate BC Security red team tool of the same name) takes a different approach,” Abnormal researchers said.  

A Commercial-grade Platform 

It is being sold openly as a commercial-grade cybercrime platform by a threat group calling itself Jinkusu. This scourge is being distributed like a SaaS solution.  

“It launches a headless Chrome instance (a browser that operates without a visible window) inside a Docker container, loads the brand’s real website, and acts as a reverse proxy between the target and the legitimate site.” 

Recipients receive genuine page content directly through the malefactor’s infrastructure, so the phishing page is always up to date. Moreover, because Starkiller proxies the real site live, there are zero template files for security vendors to fingerprint or blocklist. 

In this way, Starkiller’s control panel equips attackers with a polished dashboard for running phishing campaigns. The core workflow requires practically no technical skill. “An attacker enters a brand’s real URL, and the platform spins up a Docker container running a headless Chrome instance that loads the real login page.” 

MITM Reverse Proxy 

Abnormal says the container then acts as a man-in-the-middle reverse proxy, forwarding the end user’s inputs to the legitimate site and returning the site’s responses. “Every keystroke, form submission, and session token passes through attacker-controlled infrastructure and is logged along the way.” 

Starkiller also offers threat actors real-time session monitoring, so they can live-stream the target’s screen as they interact with the phishing page.  

A keylogger is included, so bad actors can capture each keystroke, cookie and session token theft for direct account takeover, geo-tracking of targets, and automated Telegram alerts when new credentials arrive.  

“Campaign analytics round out the operator experience with visit counts, conversion rates, and performance graphs—the same kind of metrics dashboard a legitimate SaaS platform would offer,” the researchers added.  

MFA Bypass 

The MFA bypass is worth noting. Since the actual end user is logging in to the actual site via the proxy server, any one-time codes or authentication tokens they provide will be relayed to the actual service in real time.  

The attacker will then harvest session cookies and tokens, giving them access to the account. When attackers relay the entire login process in real time, MFA can be bypassed even when it functions as designed. 

Starkiller’s marketing materials highlight how the platform is designed for financial fraud, with advertised modules for harvesting credit card numbers, crypto wallet seeds, bank accounts, and payment details. The platform also advertises fake software update templates for browsers such as Chrome and Firefox, which are intended to deceive victims into downloading spurious files, as well as an EvilEngine Core module that boasts undetectable phishing links. 

The platform also automatically handles all operational infrastructure. Docker engine status, image builds, and active containers are managed from one panel, meaning attackers don’t need to understand reverse proxies or certificate management to carry out an attack.  

The low technical barrier is what makes Starkiller particularly dangerous, Abnormal said. 

MFA Isn’t Impenetrable 

Javvad Malik, Lead Security Awareness Advocate at KnowBe4, commented: “MFA is an essential part of keeping accounts secure, but like anything, it isn’t an impenetrable forcefield. Attackers still target humans to build trust and get them to willingly hand over credentials or grant access.” 

He says we can only expect more MFA-bypass with realtime phishing, which is why t’s important to prioritise phishing-resistant MFA such as FIDO2, because not all MFA is created equally. 

“Beyond that, organizations should invest in controls to detect unknown logins from new locations or devices and have response plans in place. Also, organizations need to train their users so they can pause and verify whenever anything appears suspicious.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read

Clipping Scripted Sparrow’s Wings: How Fortra Traced a Global Phishing Ring

December 19, 20256 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}