Starkiller is an adversary-in-the-middle phishing-as-a-service platform associated with a group referred to as Jinkusu. It is used to impersonate major online brands and Microsoft 365 login workflows by proxying legitimate authentication pages rather than relying on static phishing templates. This design allows operators to capture credentials, one-time passcodes, session cookies, and authentication tokens while victims interact with the real service through attacker-controlled infrastructure, enabling account takeover and bypass of common MFA methods such as SMS, OTP, and push-based prompts. Starkiller has been described as a newer AiTM-as-a-service offering with a subscription dashboard, reflecting the commoditization of enterprise-grade phishing operations. The platform is notable for generating deceptive lookalike URLs and relaying traffic through attacker infrastructure while presenting the genuine proxied web experience of targeted brands including major technology companies, consumer platforms, payment services, and banks. Because it proxies real login pages, it does not depend on reusable vendor-specific templates that defenders can easily blocklist. Its operational model aligns with modern phishing infrastructure that emphasizes rapid deployment, resilience, and scalable credential and session theft rather than single static phishing pages. Starkiller’s observed capabilities center on initial access through phishing, credential theft, session hijacking, and post-authentication abuse of stolen tokens or authenticated sessions. Available reporting identifies it as a service platform rather than a state-directed intrusion set, and the dominant motivation is consistent with financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators use a phishing kit that proxies legitimate websites, generates deceptive lookalike URLs, and captures one-time codes or authentication tokens to bypass MFA and gain authenticated account access.
AiTM-as-a-service platform with a subscription dashboard used to commoditize session-stealing phishing operations.
AiTM-as-a-service platform with a subscription dashboard.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.