Comment by pests
10 hours ago
This is so odd. I tried to verify your claim and I give up. It might be but I really hate how information is becoming like this. There is other reporting out there on "Starkiller" (the phishing kit in kerbs most recent post) and I can find other articles on it, but sources seem to be circular. The source mentions Jinkusu forums, which do seem to be real, but any links I find aren't loading for me and still no conclusive findings of Starkiller.
https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B...
These forums are mostly private, but Krebs certainly has access to them. There can really be no excuse for how he handled this.
There are multiple posts by people in different places claiming to have bought this phishing kit, and then being delivered totally non-functional vibecoded garbage. The vibecoded garbage is not the advertised product though, as the author never managed to get the AI to finish his project.
I figured the forums were real, just was blocked for some reason so thanks.
I do not doubt this story for a second. Its crazy Kerb's is basically freely advertising this blackhat slop.
Krebs lack any sort of real credibility. He's pushing out slop with a govern-mentalist propaganda. Tech journalists are the worst form to gather any actual information.
Krebs has some credibility in this space because he used to post well-informed takes on these topics, not stuff like this.
His record has never been flawless, but the guy actually put in the work to learn Russian to be able to read these forums. He just doesn’t anymore.
All of his dox articles are based on sloppy practices from threat actors.
2 replies →