Jinkusu is a cybercrime operation associated with the Starkiller adversary-in-the-middle phishing platform. The group markets Starkiller as a phishing-as-a-service offering with a subscription-style dashboard and supporting user community, lowering the barrier for less-skilled criminals to conduct credential theft and account takeover operations at scale. Jinkusu has been described as maintaining an active customer forum and offering multiple cybercrime services beyond the core phishing kit. Starkiller is designed to proxy legitimate authentication pages in real time rather than relying on static cloned phishing pages. It uses a containerized browser-based reverse-proxy architecture to load genuine login content from targeted brands and relay victim interactions through attacker-controlled infrastructure. This enables theft of credentials, multi-factor authentication inputs, session cookies, and other authenticated session material, allowing session hijacking and post-authentication account compromise. Reported targeting themes include major consumer and enterprise identity providers and online platforms such as Microsoft, Google, Apple, and Facebook. Operational features attributed to the platform include centralized infrastructure management, phishing page deployment, session monitoring, deceptive URL generation, URL masking, and analytics for campaign performance. Reporting also describes real-time monitoring of active victim sessions, logging of keystrokes and form submissions, and optional harvesting of contact information from compromised sessions for follow-on phishing. The platform’s live-proxy design reduces reliance on static phishing templates and can complicate traditional detection approaches based on page fingerprinting or simple reputation controls. Jinkusu is best characterized as a financially motivated cybercrime service provider focused on commoditized phishing, credential theft, session hijacking, and related post-compromise abuse rather than as a state-linked intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator of the Starkiller AiTM-as-a-service platform.
Operator of the Starkiller AiTM-as-a-service platform.
Advertising and enabling use of the Starkiller phishing suite, which proxies legitimate login pages to bypass MFA and capture credentials/sessions; provides centralized infrastructure management, page deployment, and session monitoring to lower the barrier for phishing operations.
Operates/markets the Starkiller phishing suite as a cybercrime platform (phishing-as-a-service) that uses adversary-in-the-middle (AitM) reverse-proxying of legitimate login pages to capture credentials and session tokens, enabling MFA bypass and account takeover. Provides centralized infrastructure management, phishing page deployment, and session monitoring; supports URL masking/shorteners to obscure destinations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.