No Image Available

Article Details

Title
Article: ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Impact Score
6 / 10
AI Summary (Processed Content)

A new phishing-as-a-service platform called Starkiller uses a sophisticated man-in-the-middle technique to bypass traditional defenses. It dynamically loads the real login pages of major brands and proxies all interactions, stealing credentials, session tokens, and even multi-factor authentication codes in real time. The service provides criminals with live session monitoring, analytics, and automated alerts, effectively neutralizing MFA protections. This represents a significant evolution in phishing tactics that is likely to be copied by other threat actors.

Original URL
https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/
Source Feed
Krebs on Security
Published Date
2026-02-20 20:00
Fetched Date
2026-03-04 13:38
Processed Date
2026-03-04 14:03
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content