Cyber Security News

New Phishing Framework Starkiller Proxies Real Login Pages to Bypass MFA

A highly sophisticated phishing framework named Starkiller has recently emerged, offering attackers an advanced method to steal credentials and bypass multi-factor authentication.

Developed by a group known as Jinkusu, this malicious toolkit is sold as a commercial software-as-a-service product.

Unlike older toolkits relying on static copies of legitimate websites, this new platform loads real login pages dynamically.

This approach allows low-skill attackers to launch convincing enterprise-grade campaigns without managing complex server infrastructure.

The primary delivery channel for this threat is deceptive email messages containing malicious links. When a target clicks the link, the framework spins up a hidden web browser inside a secure container to load the actual brand website in real time.

The attacker’s server then acts as a middleman, forwarding the victim’s keystrokes, passwords, and multi-factor authentication codes directly to the legitimate service.

Because victims interact with the genuine website through a proxy, the impact is severe, leading to rapid account takeovers and widespread session hijacking.

This malicious infrastructure also includes specialized tools designed for financial fraud, capturing credit card details and cryptocurrency wallet recovery phrases.

Abnormal analysts/researchers noted or identified the malware framework’s ability to generate deceptive web addresses that visually mimic trusted domains.

Starkiller’s landing page, advertising a 99.7% success rate (Source – Abnormal)

By combining fake software update templates with advanced link obfuscation techniques, the platform tricks users and automated security scanners.

Attackers can monitor active sessions continuously from a polished control panel, capturing sensitive information without triggering immediate alarms.

Detection Evasion And Defense Strategies

Traditional security defenses struggle to stop this proxy-based approach because the framework eliminates the static files that defenders typically block.

Since the malicious server relays the exact content of the legitimate portal, page fingerprinting tools cannot distinguish fake sessions from real ones.

Platform control panel where operators paste a brand’s website URL and deploy (Source – Abnormal)

The platform integrates web address shorteners and visual masking tricks to hide the true destination of malicious links.

Starkiller’s capabilities, including MFA bypass and cookie stealing (Source – Abnormal)

To combat this threat, security teams must move away from relying solely on static page analysis and domain reputation scores.

The recommendation is to implement identity-aware security solutions that monitor for behavioral anomalies.

Defenders should actively track unusual login locations, unexpected device attributes, and instances of session token reuse.

By focusing on behavioral signals rather than static indicators, organizations can reliably detect and block these dynamic compromises.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago