Starkiller Phishing Kit Bypasses MFA via Live Proxies

Emerging phishing kits like Starkiller bypass MFA; service platforms lower skill barriers for sophisticated credential theft.

  • A new phishing kit called Starkiller uses live proxying of legitimate login pages to bypass multi-factor authentication (MFA) effectively.
  • Separate campaigns are evolving to target Microsoft 365 logins via OAuth device codes and financial institutions with sophisticated evasion chains.
  • These tools are lowering the skill barrier for cybercriminals, offering advanced capabilities in user-friendly, SaaS-style platforms.

A new, highly effective phishing tool has emerged, allowing cybercriminals to reliably bypass multi-factor authentication protections used by millions. According to researchers at Abnormal, the Starkiller platform, developed by a group called Jinkusu, operates by acting as a real-time reverse proxy between a victim and a legitimate website, serving a perfect, live copy of the login page from inside a Docker container. This method captures every keystroke and session token, making traditional security fingerprinting and blocklists ineffective.

- Advertisement -

Consequently, this technique eliminates the need for attackers to manually update their fake pages, as they always mirror the current live site. Meanwhile, the threat landscape continues to evolve with other sophisticated methods, including one campaign that compromises Microsoft 365 accounts by tricking users into entering an attacker-supplied device code on Microsoft’s own domain, granting the attacker persistent access.

Separately, financial institutions are facing a multi-stage attack that uses spoofed domains to trigger a fraudulent Cloudflare CAPTCHA page before redirecting to credential harvesting sites, as detailed by BlueVoyant. These campaigns employ advanced evasion chains with referrer validation and code obfuscation to hinder automated security tools. The rise of kits like Starkiller and the evolving 1Phish platform shows a trend toward criminal “as-a-service” offerings that centralize attack management and lower the technical barrier to entry for fraudsters.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

CoreWeave Client Core Scientific Sells Bitcoin For AI

Core Scientific sold 1,900 Bitcoin in January and expects to sell its remaining sub-1,000...

Solana Struggles to Surpass $90 Resistance Amid Volatility

Solana (SOL) faces substantial resistance at the $90 price level, having tested it multiple...

Bitcoin Holds $67K Amid ETF Outflows, Geopolitical Strains

Bitcoin is consolidating near $67,000, impacted by over $9 billion in net outflows from...

Crypto Exchanges Embed AI ‘Brains’ Into Wallets

Binance announced plans to launch a "Binance-level brain" for AI agents, embedding exchange-grade intelligence...

Riot Platforms Reports Record $647.4M Revenue in 2025

Riot Platforms reported record annual revenue of $647.4 million for 2025, a 72% increase...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!