‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
2026-03-04T21:14:04Z•4f28a0a66c97dbc0697b77ebe1faf62efdedd6c5096e0ce371686ada29a0242d
Android-TVBadboxDDoSI2PIoT-botnetKimwolfMFA-bypassMicrosoft Patch TuesdayScattered LapsusShinyHuntersStarkillerbotnetcredential-harvestingdata-ransom-gangman-in-the-middlephishingphishing-as-a-servicereal-time-proxyvulnerability-managementzero-day
What happened
Collection of KrebsOnSecurity items detailing multiple high-impact threats: a new phishing-as-a-service called “Starkiller” that proxies real login pages and relays victims’ usernames, passwords and MFA codes to legitimate sites in real time (enabling robust MFA bypass and stealthy credential harvesting); the Kimwolf IoT botnet (over 2 million devices) conducting large-scale DDoS, scanning local networks, disrupting the I2P anonymity network, and possibly compromising Badbox 2.0 infrastructure (Android TV streaming boxes); and Microsoft February 2026 Patch Tuesday addressing 50+ flaws — incl.6
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 4f28a0a66c97dbc0697b77ebe1faf62efdedd6c5096e0ce371686ada29a0242d
- Enrichment time
- 2026-03-04T21:14:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.