Starkiller Phishing Kit: How Hackers Are Bypassing Your Multi-Factor Authentication
Mar 3, 2026 // 17:06 - Lina Schonbein


Starkiller is a sophisticated phishing-as-a-service (PhaaS) platform developed by a threat group called Jinkusu. It utilizes an Adversary-in-the-Middle (AitM) reverse proxy architecture to bypass multi-factor authentication (MFA) and hijack active user sessions in real time.

Key Features & Architecture

  • Live Site Proxying: Unlike traditional kits that use static HTML clones, Starkiller launches a headless Chrome instance within a Docker container to load the target brand’s actual website.
  • AitM Reverse Proxy: It acts as a middleman between the victim and the legitimate service, relaying genuine page content while intercepting all user input.
  • MFA Bypass: Because the user interacts with the real site through the proxy, any submitted MFA codes (SMS, TOTP, etc.) are forwarded instantly, allowing the attacker to capture the resulting session cookies/tokens.
  • Advanced Evasion:
    • Residential Proxies: Uses rotating residential IP addresses to bypass geolocation-based blocking and “impossible travel” detections.
    • URL Masking: Employs techniques like the “@” symbol trick to deceive users and bypass simple domain filters.
  • User-Friendly Dashboard: Provides a polished GUI for attackers to manage campaigns, monitor live sessions, and automate alerts via Telegram.

Defensive Recommendations

Standard MFA is often ineffective against these proxy-based attacks. Security experts recommend:

  • Phish-Resistant MFA: Implementing FIDO2/WebAuthn (Passkeys) or hardware security keys that bind authentication to the specific origin URL.
  • Conditional Access Policies: Restricting sign-ins to compliant, managed devices to block authentication attempts from unauthorized attacker infrastructure.
  • Behavioral Monitoring: Watching for anomalous sign-in patterns, session token reuse from unexpected locations, and atypical travel.

#are  #authentication  #bypassing  #hackers  #how  #kit:  #multi-factor  #news  #phishing  #starkiller  #your   —   News