A new and sophisticated phishing framework, named Starkiller, is making waves in the cybercrime world.
Unlike traditional phishing kits that rely on static HTML clones of login pages, Starkiller takes a more advanced approach, using real login pages and proxying them through an attacker-controlled infrastructure.
This method allows cybercriminals to bypass Multi-Factor Authentication (MFA) protections and steal sensitive credentials more effectively.
Inside Starkiller’s Operation
Starkiller is a commercial-grade platform offered by the cybercriminal group Jinkusu, designed for launching phishing campaigns at scale.
The platform operates by launching a headless Chrome instance an invisible browser inside a Docker container, which loads the legitimate brand’s login page.
The container acts as a man-in-the-middle reverse proxy between the user and the real website. As a result, the user interacts with an authentic login page, unaware that their inputs are being intercepted and logged by the attacker.

Once a user enters their credentials or submits authentication data, the attacker receives session tokens and cookies, thereby gaining unauthorized access to their accounts.
One of Starkiller’s most dangerous features is its ability to bypass MFA. Since the attacker controls the session flow in real time, any MFA codes or tokens entered by the victim are passed directly to the legitimate service, allowing the attacker to steal them before they expire.

Targeting Users With Real-Time Phishing
The Starkiller framework offers an easy-to-use dashboard that enables cybercriminals to launch phishing campaigns with minimal technical knowledge.
With features like real-time session monitoring, attackers can track the victim’s actions as they interact with the phishing page.
The platform also includes keyloggers that capture every keystroke typed by the victim, as well as geo-tracking and automated Telegram alerts when new credentials are harvested.
To make their phishing campaigns even more convincing, Starkiller includes a URL masking tool.
This feature allows attackers to create deceptive URLs that visually resemble trusted domains like Google or Microsoft, which increases the chances of users clicking on the malicious links. The platform also integrates URL shorteners to obscure the malicious destination further.
Starkiller’s capabilities extend to financial fraud, offering modules to capture credit card numbers, crypto wallet seeds, and bank credentials.

The platform also supports fake software updates that trick victims into downloading malicious payloads. With these features, cybercriminals can run sophisticated, large-scale operations targeting a range of valuable data.
Starkiller represents a new wave of phishing attacks, making it significantly harder for traditional security measures to stop these threats.
Security tools typically rely on page fingerprinting and domain blocklisting to detect phishing attempts. However, Starkiller’s dynamic, real-time phishing pages make these defenses ineffective.
The combination of a reverse proxy that serves legitimate content and the MFA bypass feature makes it an especially dangerous tool.
To defend against Starkiller and similar frameworks, security measures must focus on behavioral analysis looking for unusual login patterns and abnormal session activities, rather than relying solely on static page content.
Identifying these suspicious behaviors early on can help protect users from falling victim to these increasingly sophisticated attacks.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.