BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Starkiller Phishing Kit Bypasses MFA via Live Proxies

Emerging phishing kits like Starkiller bypass MFA; service platforms lower skill barriers for sophisticated credential theft.

  • A new phishing kit called Starkiller uses live proxying of legitimate login pages to bypass multi-factor authentication (MFA) effectively.
  • Separate campaigns are evolving to target Microsoft 365 logins via OAuth device codes and financial institutions with sophisticated evasion chains.
  • These tools are lowering the skill barrier for cybercriminals, offering advanced capabilities in user-friendly, SaaS-style platforms.

A new, highly effective phishing tool has emerged, allowing cybercriminals to reliably bypass multi-factor authentication protections used by millions. According to researchers at Abnormal, the Starkiller platform, developed by a group called Jinkusu, operates by acting as a real-time reverse proxy between a victim and a legitimate website, serving a perfect, live copy of the login page from inside a Docker container. This method captures every keystroke and session token, making traditional security fingerprinting and blocklists ineffective.

- Advertisement -

Consequently, this technique eliminates the need for attackers to manually update their fake pages, as they always mirror the current live site. Meanwhile, the threat landscape continues to evolve with other sophisticated methods, including one campaign that compromises Microsoft 365 accounts by tricking users into entering an attacker-supplied device code on Microsoft’s own domain, granting the attacker persistent access.

Separately, financial institutions are facing a multi-stage attack that uses spoofed domains to trigger a fraudulent Cloudflare CAPTCHA page before redirecting to credential harvesting sites, as detailed by BlueVoyant. These campaigns employ advanced evasion chains with referrer validation and code obfuscation to hinder automated security tools. The rise of kits like Starkiller and the evolving 1Phish platform shows a trend toward criminal “as-a-service” offerings that centralize attack management and lower the technical barrier to entry for fraudsters.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading