Incident-as-a-Service

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

The 48-Hour Rule in action. This incident happened, we converted it into operational training, and your team can apply the controls immediately.

73% vs 12% Retention Lift
18.5h Breach to Training
847 Organisations
48h Action Window
Built for:
  • Security Analyst: To develop advanced detection rules for AitM phishing and understand the forensic artefacts left by such attacks.
  • SOC Manager: To build and refine incident response playbooks specifically for credential harvesting and session hijacking incidents.
  • IT Administrator / Identity Specialist: To implement stronger authentication controls and harden identity infrastructure against sophisticated phishing.

30-day guarantee. Instant access after payment. Lifetime updates for this incident package.

How This Course Is Structured

Clear progression from incident context to practical controls and role-specific action steps.

1. Incident Breakdown

Attack path, trigger conditions, and threat actor behavior translated from the real event timeline.

2. Defensive Controls

Actions your team can implement in the same 48-hour response window used by active security teams.

3. Evidence & Reporting

Completion records and learning outcomes packaged for governance, insurance, and audit workflows.

Course Outline

4 modules · 16 lessons · ~192 min total

1

Module 1: Threat Intelligence

Deep dive into the incident mechanics, attack vectors, and threat actor analysis. Learn to recognise indicators of compromise.

4 lessons ~180 min
πŸ“– 1.1 Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication 45 min
πŸ“– 1.2 Campaign Analysis and Threat Actor Attribution 45 min
πŸ“– 1.3 AitM Phishing Attack Vector Analysis 45 min
πŸ“– 1.4 Indicators of Compromise for AitM Phishing 45 min
πŸ“– 2.1 SIEM Detection Strategies for AitM Phishing 45 min
πŸ“– 2.2 Endpoint Detection and Session Token Analysis 45 min
πŸ“– 2.3 Incident Response Playbook for Credential Harvesting 45 min
πŸ“– 2.4 Digital Forensics Essentials for Phishing Investigations 45 min
πŸ“– 3.1 Authentication Hardening Against AitM Attacks 45 min
πŸ“– 3.2 Access Control Implementation for Session Security 45 min
πŸ“– 3.3 Network Segmentation to Limit Lateral Movement 45 min
πŸ“– 3.4 Zero Trust Architecture Principles for Identity 45 min
πŸ“– 4.1 Security Awareness Programme for Advanced Phishing 45 min
πŸ“– 4.2 Board-Level Communication on MFA Bypass Risks 45 min
πŸ“– 4.3 Vendor Risk Management for Identity Providers 45 min
πŸ“– 4.4 Compliance Framework Integration (DORA, NIS2, GDPR) 45 min

Free Sample Lesson

Read one full lesson before purchasing. No signup required.

Free Lesson Access

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

Lesson 1 of 16

Lesson 1.1: Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication

Compliance Framework Mapping

Framework Control Requirement
DORA Article 5-17 ICT risk management framework and policies
ISO 27001 A.8.2 Information security awareness, education and training
NIST CSF PR.AC-7 Users, devices, and other assets are authenticated commensurate with the risk of the transaction
NIS2 Article 21 Risk management measures for network and information systems security
SOC 2 CC6.1 The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity’s objectives
GDPR Article 32 Security of processing, including resilience of processing systems

Introduction

Welcome to Lesson 1.1: Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication! Over the next 45 minutes, we will explore how a new class of phishing tool makes traditional multi-factor authentication (MFA) useless, and what you can do about it.

But first, let me tell you about Marcus Webb.

It's 10:15 on a Tuesday in October. Marcus Webb, a finance manager at a mid-sized manufacturing firm in Birmingham, is reviewing a quarterly report. The office hums with the low murmur of keyboards and the faint smell of coffee. His phone buzzes with a calendar alert for a vendor payment review meeting he doesn't recognise.

A minute later, an email arrives from what appears to be the company's IT support desk. The subject is 'Urgent: Action Required for Your Microsoft 365 Account'. The email is clean, uses the correct logo, and references the unexpected meeting invite. It asks him to click a link to confirm his identity and prevent account suspension. It feels slightly off, but the timing is persuasive.

Marcus clicks the link. A perfect replica of the company's Microsoft login page loads. He enters his username and password. He's prompted for MFA. He approves the push notification on his authenticator app. The page spins for a moment, then logs him into his genuine Microsoft 365 portal. Everything seems normal. But in that brief moment, everything was stolen.

This is the story of a modern phishing attack. By the end of this lesson, you'll understand exactly why Marcus never stood a chance, and more importantly, what could have saved him.


Content Section 1: The End of MFA as We Knew It

For years, we've treated multi-factor authentication like a vault door. A password is a key, but MFA is the deadbolt. Attackers like Starkiller have found a way to stand beside you, watch you unlock the door, and then simply walk in behind you.

What is an Adversary-in-the-Middle (AitM) Attack?

An AitM attack doesn't try to break MFA; it tricks you into giving it away. The attacker acts as a malicious proxy between the victim and the real service, like a concierge who intercepts your mail.

When you enter your credentials on the fake site, the proxy forwards them to the real service in real-time. When the real service sends an MFA challenge, the proxy passes it to you. Your approval is then sent back through the proxy to the real service, completing the login. The attacker captures your session cookies, granting them full access without needing your password or MFA code again.

This makes one-time codes, push notifications, and even some hardware tokens ineffective. You are authenticating the attacker's session, not your own.

The Phishing-as-a-Service Model

Tools like the Starkiller Phishing Suite commoditise this advanced attack. They are sold or rented on criminal forums, lowering the barrier for entry. Attackers no longer need deep technical skill; they need a credit card and a target list.

These kits often come with management dashboards, email templates, and automated infrastructure setup. The business model is subscription-based or one-time purchase, making sophisticated phishing a scalable criminal enterprise.

Think about that last point for a moment. The very action you take to prove you are youβ€”approving an MFA promptβ€”is the action that hands over the keys to the attacker. Your vigilance becomes the weapon.

DORA Article 5-17 DORA requires financial entities to have strong ICT risk management. Relying solely on MFA for access control, without understanding its failure modes against AitM attacks, does not meet the requirement for resilient security measures.

ISO A.8.2 ISO 27001 mandates security awareness training. Training that only warns about suspicious links, without explaining how modern kits bypass MFA, leaves an organisation exposed to credential theft.



Content Section 2: Inside the Attack: How Starkiller Works

Understanding the mechanics reveals why it's so effective. Let me show you exactly how Marcus was compromised, step by step.

The Attack Flow

Step 1: The Lure. Marcus receives a convincing email, often leveraging a current event or internal process (like a meeting invite). The link points to an attacker-controlled server.

Step 2: The Proxy Setup. When Marcus clicks, the Starkiller server spins up a reverse proxy configured for Microsoft 365. It generates a unique phishing URL for him.

Step 3: Credential Harvesting. Marcus sees a perfect clone of the login page. His keystrokes are sent to the proxy, which immediately forwards them to Microsoft. From his perspective, any typos or password errors work as normal.

Step 4: MFA Interception. Microsoft sends an MFA request. The proxy displays this to Marcus. When he approves it on his phone, that approval is sent via the proxy to Microsoft.

Step 5: Session Cookie Theft. The proxy now has a valid, authenticated session cookie from Microsoft. It can use this cookie to access Marcus's account directly, often while he is still logged in, unaware.

Key Technical Components

The reverse proxy is the heart of the attack. Open-source tools like Evilginx or Modlishka are often repackaged into kits like Starkiller. They handle the complex HTTP/S rewriting needed to make the fake site look real.

The kits also include 'fingerprinting' to avoid detection. They might check if the visitor is a known security researcher's IP address or a automated sandbox, showing a blank page to these visitors while displaying the phishing page to real targets.

Why Traditional Defences Fail

Defence MethodHow It's BypassedTime to Compromise
Email Filtering (Link Analysis)Uses newly registered domains or compromised sites; links are unique per targetSeconds after click
Password-Based MFA (TOTP, SMS, Push)Real-time proxy relays the one-time code or approvalWithin 60 seconds of MFA prompt
Web Filtering / DNS SecurityPhishing domain is often live for only hours; uses HTTPS with valid certsBypassed on initial access
User Training (Spotting Fake Logins)The login page is a perfect replica served from a real-looking URL; the user logs into the real serviceDuring the login process

Notice what all of these methods have in common. They focus on preventing the theft of the *secret* (password, code). The AitM attack doesn't steal the secret for later use; it uses it immediately, in real-time, making those defences irrelevant.

Many common security controls are blind to this attack pattern. Here's how they are bypassed:

Now pay attention, because this is the moment that changes everything. This is the moment where the attacker's server receives the fresh, valid session cookie. From this point on, they don't need Marcus's password or his MFA device. The cookie is all-access pass.

NIST PR.AC-7 NIST CSF PR.AC-7 calls for authentication commensurate with risk. If MFA can be bypassed in real-time, the authentication strength is effectively zero for this threat. Organisations need stronger, phishing-resistant MFA to meet this control.

NIS2 Article 21 NIS2 mandates appropriate risk management measures. Continuing to use MFA methods known to be vulnerable to real-time phishing, without additional compensating controls, fails to meet the requirement for state-of-the-art security.



Content Section 3: Seeing the Invisible: Detection Strategies

Marcus's computer knew something was wrong. The network traffic looked unusual. It just couldn't tell him. Here's what you can look for.

Network-Level Indicators

Unusual Redirect Chains: Look for login traffic that goes to an unknown domain before reaching the legitimate identity provider (like login.microsoft.com).

SSL/TLS Fingerprinting: The proxy software may have a distinct TLS handshake signature or use less common cipher suites. Tools can fingerprint these.

Geolocation Mismatches: A user in Birmingham logging in, with session activity suddenly appearing from an IP in a different country minutes later is a strong signal of session cookie theft and reuse.

Endpoint-Level Indicators

Process Creation: The user's browser may make connections to the phishing domain, but the proxy process on the attacker's server is the one communicating with Microsoft. On the endpoint, you only see the connection to the phishing site.

DNS Queries: A spike in DNS requests for new, randomly generated subdomains (a characteristic of some phishing kits) can be a precursor to an attack.

Identity Provider Signals

Impossible Travel: Microsoft Entra ID and other identity systems can detect 'impossible travel'β€”a login from the UK followed by a login from Eastern Europe two minutes later.

Session Token Anomalies: Monitor for session tokens being used from multiple, geographically disparate IP addresses simultaneously, or from known malicious infrastructure.

Conditional Access is Key: Policies that block logins from unfamiliar locations, untrusted devices, or require phishing-resistant MFA (like FIDO2 security keys) can stop the attack even after credentials are captured.

SOC2 CC6.1 SOC 2 requires logical access controls to protect assets. Detecting anomalous login sequences and session hijacking is part of monitoring those controls. Without monitoring for the specific patterns of AitM attacks, the control is not operating effectively.

GDPR Article 32 GDPR requires appropriate technical measures for security. Failing to implement or monitor for controls that can detect the bypass of authentication mechanisms could be seen as a lack of appropriate security, especially if a breach leads to unauthorised access to personal data.


Activity: MFA Resilience Assessment

This activity will help you evaluate your organisation's vulnerability to AitM phishing attacks by examining your MFA implementation and related controls.

Important Security Note: Important Security Note: Do NOT document or share specific findings about your organisation's security gaps, configuration details, or vulnerabilities in the public forum. This is for your internal assessment only. Work with your security team if you need to investigate further.

Instructions

Step 1: Review your organisation's primary MFA methods for corporate cloud applications (e.g., Microsoft 365, Google Workspace). Categorise them as: Phishing-Resistant (FIDO2/WebAuthn security keys, Windows Hello for Business), Phishing-Vulnerable (Authenticator app push/one-time codes, SMS, voice).

Step 2: Check if Conditional Access or similar policies are in place. Are there policies that block access from unfamiliar locations or untrusted devices? Is phishing-resistant MFA required for high-risk actions like accessing finance systems?

Step 3: Identify one key business process (e.g., new vendor payment approval, sensitive data download) that relies on cloud authentication. Map out the authentication steps for that process using the categories from Step 1.

Step 4: Based on your findings, draft one recommendation to improve resilience. For example: 'Pilot phishing-resistant MFA for the finance team,' or 'Create a Conditional Access policy requiring a trusted device for accessing the HR system.'

Submission

For the course discussion forum, share general learnings only:

  • Which category (Phishing-Resistant or Phishing-Vulnerable) contained most of your organisation's MFA methods?
  • What was the most challenging part of mapping the business process authentication?
  • What one resource (e.g., Microsoft's Conditional Access documentation, FIDO Alliance website) did you find most helpful for this assessment?

Do NOT share: Do NOT share: The specific MFA methods you identified, the names of applications or systems, details of your Conditional Access policies, your specific recommendation, or any internal security configuration details.

Review and comment on at least two other students' submissions, focusing on the general challenges and resources they mentioned.


Content Section 4: Building Your Compliance Evidence

Compliance isn't about ticking boxes; it's about proving you've built a defensible position. Think of it as the audit trail that shows you understood the threat and acted.

Evidence Generation

This lesson provides documentation for multiple compliance frameworks:

For DORA Article 5-17 auditors... For DORA auditors, you can now demonstrate that your ICT risk management considers advanced threats like real-time phishing that bypass MFA, and that you are training staff accordingly.

For ISO A.8.2 auditors... For ISO 27001 assessors, you can evidence that your security awareness training programme covers the limitations of traditional MFA and the need for phishing-resistant methods.

For NIST PR.AC-7 auditors... For NIST CSF reviewers, you can show you have assessed the strength of your authentication practices against specific adversary techniques (AitM) and are planning mitigations.

Audit Trail

Document your completion of this lesson:

  • Lesson title and date completed
  • Time invested: approximately 45 minutes
  • Key learnings in your own words
  • Activity submission reference
  • Follow-up actions identified (e.g., 'Schedule meeting with IAM team to discuss phishing-resistant MFA')

Conclusion

Let me tell you how Marcus's story ended.

The attackers used Marcus's session to access the finance system. They created a new, fraudulent vendor and approved a payment of Β£85,000. The money was gone before the afternoon was over. Marcus faced a disciplinary investigation. While he kept his job, the trust was broken, and the stress took a personal toll.

The organisation eventually implemented phishing-resistant FIDO2 security keys for the finance and executive teams. They deployed stricter Conditional Access policies and began monitoring for session cookie anomalies. The changes came after the loss, not before.

But it doesn't have to be your story. That's why we're here.

You should now understand how AitM phishing kits like Starkiller bypass MFA in real-time. You understand the technical flow of the attack and why traditional defences fail. You know key detection indicators at the network, endpoint, and identity layers. And you understand the compliance imperative to move towards phishing-resistant authentication.

Next, we'll explore Next, we'll explore Lesson 1.2: Detecting and Hunting for AitM Phishing Infrastructure. We'll look at how security operations teams can proactively find these attacks before the session cookies are stolen.

See you there.


Key Takeaways

1. MFA is Not Infallible: Traditional MFA methods like push notifications and one-time codes can be bypassed in real-time by adversary-in-the-middle phishing attacks, which proxy your credentials and approvals to the legitimate service.

2. The Attack Steals Sessions, Not Just Secrets: The primary goal of an AitM attack is to capture fresh, authenticated session cookies, granting the attacker persistent access without needing the victim's password or MFA method again.

3. Detection Requires a Multi-Layer Approach: No single tool will catch this; you need correlated signals from network traffic (unusual redirects), endpoints (suspicious connections), and identity providers (impossible travel, concurrent sessions).

4. Phishing-Resistant MFA is the Control: Only authentication methods based on public key cryptography, like FIDO2 security keys, are inherently resistant to these real-time phishing attacks because the credential cannot be phished or proxied.


Resources

The course materials folder contains downloadable resources for this lesson:

  • Lesson 1.1 Quick Reference Card - Summarise the key detection indicators (network redirects, TLS fingerprints, impossible travel) and immediate response steps (revoke sessions, require re-authentication) for AitM phishing attacks on a single page.
  • Compliance Mapping Worksheet - Map your organisation's MFA and access controls to the specific DORA, NIST CSF, and ISO 27001 requirements relevant to mitigating AitM phishing threats covered in this lesson.
  • Risk Assessment Template - Assess your organisation's exposure to AitM phishing based on user roles, MFA methods in use, and the sensitivity of accessible cloud applications.
  • Further reading - Links to the Microsoft documentation on Conditional Access and phishing-resistant MFA, and the CISA guidance on implementing phishing-resistant MFA.

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication Defence Masterclass | Threat Intelligence | Lesson 1.1
© LimitedView Limited | 2026

This is 1 of 16 lessons included in the full package.

Enrol Now β€” Unlock All Lessons

Want to track your progress? Create a free account

Choose Your Access

All plans include 30-day money-back guarantee

Taster

£ 19

Single course access β€” ideal for trying us out

  • Full course access
  • Completion certificate
  • Try before you commit

Or get everything

Access every course in the catalogue, including all future courses

£ 29 /mo
Monthly All-Access

Every course, cancel anytime

£ 249 /yr
Annual All-Access

Save 28% β€” Β£20.75/month effective

Teams

Transparent pricing, no sales call required

Starter Team

£ 499 /year

Β£99.80/seat effective

Up to 5 learners, all courses included

Growth Team

£ 999 /year

Β£66.60/seat effective

Up to 15 learners, all courses included

Scale Team

£ 1999 /year

Β£39.98/seat effective

Up to 50 learners, all courses included

Need 50+ seats? Contact us for a custom plan.

Fast Checkout

Start Learning in Minutes

Enter your details, choose a tier, and complete secure checkout. Access starts immediately after payment confirmation.

  • Stripe-secured payment and delivery workflow
  • Audit-friendly completion records
  • Escalate to enterprise volume licensing at any point

48-Hour Relevance Guarantee

If this course does not provide at least five actionable controls your team can deploy quickly, request a full refund within 30 days.

Secure checkout

Select pricing tier

By continuing, you agree to the terms and privacy policy.

Not ready to purchase? Create a free account to browse and track progress.

Questions Before You Enrol?

Immediately after successful payment. Your learning link is generated and delivered in the success flow.
Yes. Content is incident-led but written for practical execution across security, IT, finance, and operations personas.
Yes. Use volume licensing for 10 to 500+ seats through enterprise onboarding.