# 'Starkiller' Phishing-as-a-Service Platform Proxies Real Login Pages to Bypass MFA


## The Threat


A sophisticated new phishing-as-a-service (PhaaS) platform dubbed "Starkiller" is raising alarms across the cybersecurity community for its ability to defeat multi-factor authentication by acting as a real-time proxy between victims and legitimate login pages. Unlike traditional phishing kits that rely on static replicas of login portals — pages that quickly become outdated and are routinely flagged by security vendors — Starkiller dynamically mirrors authentic websites, capturing credentials and session tokens as they are generated, rendering even hardware-based MFA protections largely ineffective.


The platform represents a significant evolution in the commoditization of advanced phishing techniques, making capabilities once reserved for nation-state actors and sophisticated criminal groups available to virtually anyone willing to pay a subscription fee.


## Background and Context


Phishing remains the most prolific initial access vector in cyberattacks, accounting for the majority of breaches reported annually. The security industry has spent years developing countermeasures: browser-based warnings, domain reputation systems, email filtering, and most critically, multi-factor authentication. MFA adoption has surged in recent years, with organizations increasingly mandating it for employee access to email, VPNs, and cloud services.


But the arms race has not stood still. Adversary-in-the-middle (AiTM) phishing attacks — where the attacker interposes a reverse proxy between the victim and the real service — have emerged as the primary technique for circumventing MFA. Tools like Evilginx, Modlishka, and Muraena demonstrated the concept in open-source form, but deploying them required meaningful technical skill: configuring reverse proxies, managing SSL certificates, handling DNS, and evading detection.


Starkiller changes that equation. By packaging AiTM phishing into a turnkey service with a polished web interface, customer support, and regularly updated evasion techniques, it dramatically lowers the barrier to entry. Subscribers reportedly receive access to a management dashboard where they can select target organizations, customize lure pages, and harvest stolen credentials and session cookies — all without writing a single line of code.


## Technical Details


At its core, Starkiller operates as a reverse proxy phishing framework. When a victim clicks a phishing link, their browser connects to a Starkiller-controlled server, which in turn connects to the legitimate target website — be it Microsoft 365, Google Workspace, Okta, or any other identity provider. The victim sees the real login page, rendered pixel-perfectly because it *is* the real page, served through the proxy.


When the victim enters their username and password, those credentials pass through the Starkiller proxy to the real service. When the service prompts for a second factor — a push notification, a one-time code from an authenticator app, or even a hardware security key challenge — that prompt is relayed back to the victim through the proxy. The victim completes the MFA challenge believing they are interacting with the legitimate service. The proxy captures the resulting session cookie, granting the attacker full authenticated access to the victim's account.


This technique defeats most forms of MFA because the authentication is happening against the real service in real time. Time-based one-time passwords (TOTP), SMS codes, and push-based approval methods are all vulnerable because the proxy captures the session token *after* successful authentication, not the second factor itself.


Several technical features distinguish Starkiller from earlier AiTM tools. The service reportedly employs advanced bot detection evasion, using techniques such as JavaScript fingerprinting challenges and CAPTCHA gates to prevent automated security scanners from analyzing phishing pages. It also rotates infrastructure rapidly, using ephemeral cloud instances and domain generation algorithms to stay ahead of blocklist-based defenses. The phishing pages are served over HTTPS with valid certificates, and URLs are crafted to closely resemble legitimate service domains using homoglyph characters and subdomain tricks.


Reports indicate the platform also includes an "anti-detection" module that monitors for known security researcher IP ranges, VPN exit nodes commonly used by threat intelligence teams, and headless browser signatures — automatically serving benign content to anyone who matches these profiles while reserving the phishing payload for genuine targets.


## Real-World Impact


The implications for organizations are severe. MFA has been positioned as a cornerstone of zero-trust security architectures, and many compliance frameworks treat it as a compensating control for password-based authentication risks. A tool that reliably bypasses MFA at scale undermines a critical layer of defense that billions of dollars in enterprise security spending has been built upon.


Session token theft is particularly dangerous because it can grant persistent access even after a victim changes their password or revokes their MFA device. Attackers who harvest session cookies can replay them from their own infrastructure, accessing email, cloud storage, and internal applications without triggering additional authentication challenges.


For industries handling sensitive data — healthcare, financial services, government, and critical infrastructure — Starkiller-style attacks pose regulatory and operational risks. A single compromised administrative account can lead to mass data exfiltration, business email compromise fraud, or lateral movement into production environments.


## Threat Actor Context


Starkiller is marketed on underground forums and invite-only Telegram channels, with subscription tiers reportedly ranging from a few hundred dollars per month for basic access to several thousand for premium features including dedicated infrastructure and priority support. The operators maintain an air of professionalism, offering service-level agreements and even a bug bounty program for their own platform.


The developers behind the service remain anonymous, though security researchers have noted linguistic patterns and operational hours suggesting an Eastern European origin. The platform's documentation is available in English and Russian.


The service model mirrors the broader trend of cybercrime-as-a-service, where specialized operators build and maintain attack infrastructure while their customers — ranging from low-skill opportunists to organized criminal groups — handle targeting and monetization. This division of labor has proven devastatingly effective across ransomware, initial access brokerage, and now phishing.


## Defensive Recommendations


Organizations should take several immediate steps to mitigate the threat posed by AiTM phishing platforms:


  • Deploy phishing-resistant MFA: FIDO2/WebAuthn hardware security keys and passkeys are the only MFA methods that are inherently resistant to AiTM attacks. These protocols bind authentication to the specific domain, meaning a proxy on a different domain cannot relay the challenge. Organizations should prioritize migrating high-value accounts to FIDO2-based authentication.

  • Implement token binding and conditional access policies: Cloud identity providers such as Microsoft Entra ID and Google Workspace offer conditional access policies that can detect and block token replay from unrecognized devices or locations. Enabling these controls adds a layer of defense even if a session token is stolen.

  • Monitor for anomalous session behavior: Security teams should watch for indicators of session hijacking, including impossible travel patterns, sudden changes in user-agent strings, and access from IP addresses that diverge from established baselines.

  • Enhance email and URL filtering: While Starkiller's evasion techniques are sophisticated, layered defenses including real-time URL scanning, domain age analysis, and AI-based email threat detection can catch a meaningful percentage of phishing attempts before they reach end users.

  • Conduct targeted security awareness training: Employees should be trained to recognize the subtle signs of proxy-based phishing, including unusual URL structures and unexpected certificate warnings. However, organizations should not rely solely on user vigilance — technical controls must be the primary defense.

  • ## Industry Response


    The security community has responded with increased focus on AiTM phishing detection. Several threat intelligence firms have published indicators of compromise associated with Starkiller infrastructure, and browser vendors are exploring mechanisms to detect reverse proxy interception in real time.


    Microsoft and Google have both strengthened their conditional access and continuous access evaluation capabilities in response to the growing AiTM threat. The FIDO Alliance has accelerated its push for passkey adoption, framing it as the definitive answer to phishing — a position that AiTM tools like Starkiller only reinforce.


    Law enforcement agencies in multiple jurisdictions are reportedly investigating the platform's operators, though the service's use of bulletproof hosting and cryptocurrency payments presents familiar challenges for takedown efforts.


    The emergence of Starkiller underscores an uncomfortable reality: the security industry's most widely deployed authentication defense is fundamentally vulnerable to a class of attack that is now available as a subscription service. The path forward requires a decisive shift toward phishing-resistant authentication standards — and an honest reckoning with the limitations of the defenses organizations have relied upon for too long.


    ---


    **