logo

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

ID: fe4cc437-9f73-5234-8e95-5b318936f20e

STIX ID: report--fe4cc437-9f73-5234-8e95-5b318936f20e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Researchers disclosed the Starkiller phishing suite and related phishing-as-a-service tooling that proxy real login pages via headless Chrome in Docker to capture keystrokes, session tokens, and MFA elements; the report also covers an OAuth device-code phishing campaign compromising Microsoft 365 accounts and a multi-stage campaign targeting U.S. banks using .co.com spoof domains, CAPTCHA delays, and obfuscation to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.