Starkiller Phishing Service Relays Login Credentials and MFA Codes

THE BRIEF
Krebs on Security reports that “Starkiller” is a phishing-as-a-service offering designed to relay interactions with a legitimate target website rather than present only a static imitation. According to the report, the service uses disguised links to load the target brand’s real site, then positions itself between the visitor and that site. It forwards the visitor’s username, password, and multi-factor authentication (MFA) code to the legitimate service and returns the service’s responses. Krebs describes this approach as a way to sidestep some common weaknesses of conventional phishing pages, which can be identified and removed by anti-abuse activists and security firms. The report also says many phishing kits require customers to handle server configuration, domains, certificates, proxy services, and related technical work. Starkiller is presented as a service intended to reduce that setup burden. The supplied report excerpt does not identify affected organizations or provide confirmed victim, loss, or campaign-scale information.
WHY IT MATTERS
A phishing relay can make a malicious page harder to distinguish from a genuine online destination because the target site is loaded dynamically and responses are passed back to the visitor. The reported forwarding of usernames, passwords, and MFA codes also shows why possession of an MFA code alone may not establish that a sign-in request is trustworthy. Organizations should consider how disguised links, live-site relays, and authentication workflows affect their ability to detect and interrupt suspicious access attempts.
WHO SHOULD CARE
Identity, fraud, security, and digital banking teams should care, particularly those responsible for protecting customer or workforce sign-ins. Website owners and anti-abuse teams may also want to understand how live-site relays can complicate takedown and detection efforts.
WHAT TO DO NOW
- Review sign-in telemetry for unusual combinations of new links, locations, devices, or sessions around authentication events.
- Train users to treat unexpected login links cautiously, even when the destination appears to be a familiar brand’s real website.
- Evaluate whether authentication controls can distinguish a genuine user-initiated sign-in from a relayed or otherwise suspicious session.
- Coordinate security, fraud, and anti-abuse teams on procedures for reporting and investigating suspected phishing links and relay activity.