Mark RadarMARK RADAR
EN
Event File FINTECH Phishing

Starkiller Phishing Framework Uses AiTM Tactics to Bypass MFA

1 reports · First detected 2026-03-03 · Last active 2026-03-03

Multi-factor authentication, or MFA, is designed to reduce the risk of account takeovers after passwords are compromised, but attackers are increasingly turning to adversary-in-the-middle, or AiTM, attacks. These attacks use a reverse proxy between users and legitimate websites to steal credentials and authenticated session cookies simultaneously, posing a threat to corporate email and cloud accounts.

Cybersecurity company Abnormal AI recently disclosed Starkiller, an emerging phishing framework that relays genuine login pages in real time, giving victims what appears to be a normal sign-in experience. Attackers can simultaneously intercept login credentials, MFA authentication results and session data, enabling them to take over accounts. Reports did not provide the exact disclosure date, the number of victims or the amount of losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR