Starkiller is a sophisticated phishing-as-a-service (PhaaS) platform developed by a threat group called Jinkusu. It utilizes an Adversary-in-the-Middle (AitM) reverse proxy architecture to bypass multi-factor authentication (MFA) and hijack active user sessions in real time.
Key Features & Architecture
- Live Site Proxying: Unlike traditional kits that use static HTML clones, Starkiller launches a headless Chrome instance within a Docker container to load the target brand’s actual website.
- AitM Reverse Proxy: It acts as a middleman between the victim and the legitimate service, relaying genuine page content while intercepting all user input.
- MFA Bypass: Because the user interacts with the real site through the proxy, any submitted MFA codes (SMS, TOTP, etc.) are forwarded instantly, allowing the attacker to capture the resulting session cookies/tokens.
- Advanced Evasion:
- Residential Proxies: Uses rotating residential IP addresses to bypass geolocation-based blocking and “impossible travel” detections.
- URL Masking: Employs techniques like the “@” symbol trick to deceive users and bypass simple domain filters.
- User-Friendly Dashboard: Provides a polished GUI for attackers to manage campaigns, monitor live sessions, and automate alerts via Telegram.
Defensive Recommendations
Standard MFA is often ineffective against these proxy-based attacks. Security experts recommend:
- Phish-Resistant MFA: Implementing FIDO2/WebAuthn (Passkeys) or hardware security keys that bind authentication to the specific origin URL.
- Conditional Access Policies: Restricting sign-ins to compliant, managed devices to block authentication attempts from unauthorized attacker infrastructure.
- Behavioral Monitoring: Watching for anomalous sign-in patterns, session token reuse from unexpected locations, and atypical travel.