session hijacking
-
Starkiller phishing suite proxies live login pages to bypass MFA
Researchers disclosed Starkiller, a phishing suite that proxies live login pages through attacker controlled headless browsers to capture keystrokes, session tokens and MFA codes. The toolkit centralises deployment and uses URL masking to hide destinations.
-
Handala targeted Telegram accounts of two Israeli officials
In December 2025 Handala posted about 1,900 Telegram chat entries tied to two Israeli officials. Most entries were empty contact cards and only about 40 contained messages, indicating account access rather than full phone compromise.


