logo

‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

ID: 578a4e09-c4ad-5eee-853e-f34eda2cd87d

STIX ID: report--578a4e09-c4ad-5eee-853e-f34eda2cd87d

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Abnormal AI analyzed 'Starkiller', a phishing-as-a-service offered by a group calling itself Jinkusu that dynamically loads legitimate login pages in headless Chrome containers and proxies victims’ interactions to capture credentials, MFA codes, session cookies, keystrokes, and other data; the platform includes URL masking, session hijacking, geo-tracking, analytics, and automated alerts, effectively enabling real-time account takeover and lowering the barrier to entry for low-skilled criminals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.