Best-in-Class 'Starkiller' Phishing Kit Bypasses MFA
ID: 22827f1a-a688-5d03-9539-c75f97a6ae5e
STIX ID: report--22827f1a-a688-5d03-9539-c75f97a6ae5e
Feed Name: Dark Reading
Abnormal AI researchers detail 'Starkiller', a phishing-as-a-service platform that proxies legitimate login pages via containerized headless browsers to harvest credentials and session tokens—even after MFA—while providing a SaaS-like GUI for campaign deployment, URL masking, and session monitoring; this automation lowers the skill barrier for sophisticated phishing and allows attackers to evade traditional static detections, so defenders should prioritize behavioral and identity-aware detection of anomalous sessions and token reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
