‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
2026-03-04T21:12:16Z•01f77aa57df750bdb4cf05edf59e0f89f3828d789ccfec4fa4b39a6905bbbb2c
AisuruBadboxDDoSI2PMFA-bypassSLSHScattered-LapsusStarkillercredential-harvestdata-extortionincident-responseiot-botnetkimwolfmicrosoftnetwork-segmentationpatch-tuesdayphishingphishing-as-a-servicezero-day
What happened
Multiple high-impact threats reported across February 2026: a new phishing-as-a-service called “Starkiller” proxies victims to legitimate login pages to capture usernames, passwords and MFA codes in real time (effectively enabling MFA bypass); the Kimwolf IoT botnet has grown to millions of devices, is disrupting the I2P anonymity network, performing local-network scanning and enabling large-scale DDoS and anonymized C2 relay activity (including ties to Badbox 2.0/Aisuru); and Microsoft’s recent Patch Tuesday releases fix dozens of vulnerabilities including multiple actively exploited zero‑day
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 01f77aa57df750bdb4cf05edf59e0f89f3828d789ccfec4fa4b39a6905bbbb2c
- Enrichment time
- 2026-03-04T21:12:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.