TL;DR

Starkiller is a sophisticated phishing-as-a-service that uses actual login pages as relay points, stealing credentials and MFA codes efficiently.

What happened

A new phishing service named Starkiller has emerged. It uses real websites’ login pages to steal usernames, passwords, and MFA codes without raising suspicion.

Why it matters for ops

This technique bypasses traditional security measures by leveraging actual login interfaces, making detection challenging for anti-abuse efforts and security tools.

Action items

  • Update phishing detection systems to identify proxy relay patterns
  • Warn users about suspicious links that load real websites but seem off
  • Implement stricter MFA protocols beyond simple codes

Source link

https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/