New Starkiller Phishing Framework Uses Real Login Pages to Bypass MFA Security
ID: 9e700a40-ce82-5f64-b05e-9772f13d0e14
STIX ID: report--9e700a40-ce82-5f64-b05e-9772f13d0e14
Feed Name: GBHackers
Starkiller is a phishing-as-a-service framework that runs headless Chrome in Docker to reverse-proxy genuine login pages to victims, capturing credentials and session cookies (including those issued after MFA), and offers features such as live session monitoring, keystroke logging, URL masking, analytics, and modules for financial data theft; defenders are advised to treat this as large-scale session hijacking and prioritize phishing-resistant authentication, token/session monitoring and tighter URL/email controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
