Site navigation

“Starkiller” Phishing Kit Livestreams Victims’ Logins

Tom Quinn

,

starkiller phishing kit
The SaaS‑style platform loads real brand websites inside attacker‑controlled infrastructure, capturing credentials, MFA codes and session tokens in real time.

Security researchers at Abnormal have uncovered a next‑gen phishing kit that hijacks a brand’s real website to lure victims into live, interactive sessions that capture every keystroke and credential – without any technical skill required.

Detailing its findings in a blog post, Abnormal said that the “Starkiller” kit is being sold like a SaaS product, offering hackers a commercial-grade cyber-crime platform that transforms legitimate sites into attacker-controlled infrastructure.

After simply entering a brand’s real URL, Starkiller launches a headless browser (one that operates without a visible window) in a Docker container, a self‑contained environment that has everything an application needs to run, including code, libraries, system tools, and settings.

The kit then loads a brand’s genuine login page and quietly inserts itself between the user and the legitimate site, intercepting everything they type, including MFA tokens, one-time codes, credentials, and session tokens, allowing for direct account takeover.

All of this is funnelled through the attacker’s servers and recorded, but Starkiller also lets hackers watch in real time as unwitting users interact with the phishing page. 

Adding to the subterfuge, Starkiller also provides cyber-crims with a dedicated URL masking tool that can mimic the domains of brands like Google, Microsoft, and Amazon with just one click, and customise them to their needs.  

“When recipients click a Starkiller phishing link, they are presented with the legitimate site rendered in real time—for example, a Microsoft login portal,” said researchers.

“The target types their credentials into what is an authentic Microsoft login form, but because the traffic passes through the attacker’s server, every input is captured in transit. 

“Meanwhile, on the cybercriminal’s side, the Active Targets dashboard shows the target’s session in real time, including their location, device type, IP address, and whether the session is still active.”

Abnormal said that marketing materials suggest the platform had been built for fraud, with developers advertising it as a means of stealing credit card numbers, bank details, and crypto wallet seeds.


Recommended reading


However, Starkiller was not designed as a static tool, warned researchers, with its operators taking on “customer” feedback to design new features and troubleshoot deployments. This has resulted in ongoing development, which Abnormal said will make the phishing platform “increasingly difficult” to detect.

“Traditional detection approaches—including static page analysis, domain blocklisting, and reputation-based URL filtering—are insufficient when frameworks like Starkiller dynamically generate phishing pages for each session,” said the firm.

“Detection needs to shift toward behavioural signals: anomalous login patterns, session token reuse from unexpected locations, and identity-aware analysis that can catch a compromised session even when the phishing page itself looks perfect.”


Join the Conversation at ITSX Summit

How is customer service and IT support evolving in the age of AI, automation, and digital transformation?

Join us at the ITSX Summit in Edinburgh on 5th March, to unpack the future of ITSM, ESM, Self Service, and User Experience.

The event will bring together senior leaders from IT, Service Management, and UX, providing an ideal forum for shared learning, collaboration, and high-level networking.

Register now to secure your free place at ITSX Summit.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data