‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

2026-03-04T21:14:04Z4f28a0a66c97dbc0697b77ebe1faf62efdedd6c5096e0ce371686ada29a0242d
Android-TVBadboxDDoSI2PIoT-botnetKimwolfMFA-bypassMicrosoft Patch TuesdayScattered LapsusShinyHuntersStarkillerbotnetcredential-harvestingdata-ransom-gangman-in-the-middlephishingphishing-as-a-servicereal-time-proxyvulnerability-managementzero-day

What happened

Collection of KrebsOnSecurity items detailing multiple high-impact threats: a new phishing-as-a-service called “Starkiller” that proxies real login pages and relays victims’ usernames, passwords and MFA codes to legitimate sites in real time (enabling robust MFA bypass and stealthy credential harvesting); the Kimwolf IoT botnet (over 2 million devices) conducting large-scale DDoS, scanning local networks, disrupting the I2P anonymity network, and possibly compromising Badbox 2.0 infrastructure (Android TV streaming boxes); and Microsoft February 2026 Patch Tuesday addressing 50+ flaws — incl.6

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
4f28a0a66c97dbc0697b77ebe1faf62efdedd6c5096e0ce371686ada29a0242d
Enrichment time
2026-03-04T21:14:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.