‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

2026-03-04T21:12:16Z01f77aa57df750bdb4cf05edf59e0f89f3828d789ccfec4fa4b39a6905bbbb2c
AisuruBadboxDDoSI2PMFA-bypassSLSHScattered-LapsusStarkillercredential-harvestdata-extortionincident-responseiot-botnetkimwolfmicrosoftnetwork-segmentationpatch-tuesdayphishingphishing-as-a-servicezero-day

What happened

Multiple high-impact threats reported across February 2026: a new phishing-as-a-service called “Starkiller” proxies victims to legitimate login pages to capture usernames, passwords and MFA codes in real time (effectively enabling MFA bypass); the Kimwolf IoT botnet has grown to millions of devices, is disrupting the I2P anonymity network, performing local-network scanning and enabling large-scale DDoS and anonymized C2 relay activity (including ties to Badbox 2.0/Aisuru); and Microsoft’s recent Patch Tuesday releases fix dozens of vulnerabilities including multiple actively exploited zero‑day

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
01f77aa57df750bdb4cf05edf59e0f89f3828d789ccfec4fa4b39a6905bbbb2c
Enrichment time
2026-03-04T21:12:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.