Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor Meta
Summary
Hide ▲
Show ▼
A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-skill cybercriminal customers. The service lets users impersonate major brands, generate deceptive URLs, and relay victim credentials and tokens through a Docker-hosted browser. That shift commoditizes phishing infrastructure and weakens traditional defenses such as domain blocklisting and static page analysis.
Related Happenings
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
REF6045 ClickFix banking fraud campaign targeting Mexican financial users
Campaign
H score36
First: 08.07.2026 15:52
Last: 08.07.2026 15:52
Sources 1
About this happening:
The REF6045 campaign is actively targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges, using ClickFix lures to push victims...
REF6045 ClickFix banking fraud campaign targeting Mexican financial users
CampaignAbout this happening: The REF6045 campaign is actively targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges, using ClickFix lures to push victims...
Timeline
-
20.02.2026 22:00 2 articles · 4mo ago
Starkiller phishing service analysis
Technical Analysis UpdateAbnormal AI's analysis describes Starkiller, a phishing-as-a-service operation tied to Jinkusu, that lets customers impersonate brands such as Apple, Facebook, Google, and Microsoft, loads a live login page through attacker-controlled infrastructure, and relays account holders' usernames, passwords, MFA codes, cookies, and session tokens through a Docker-hosted headless Chrome reverse proxy while also supporting keylogger capture, Telegram alerts, geo-tracking, and campaign analytics.
Show sources
- ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA — krebsonsecurity.com — 20.02.2026 22:00
- ‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA — krebsonsecurity.com — 20.02.2026 22:00