# Navigating the Rise of Starkiller and the Future of Session Hijacking with Frank McKenna Page: https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna Text version: https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna.md Podcast: [Fraudology Podcast with Karisse Hendrick](https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872) Published: 2026-03-17T08:30:00+00:00 Episode link: https://fraudology-podcast.captivate.fm/episode/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna Audio file: https://episodes.captivate.fm/episode/084fe2ce-ee81-47a2-b83e-4ffb99309c44.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/fraudology-podcast-with-karisse-hendrick-1368872/episodes/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna Duration seconds: 2069 ## Resource In this episode of Fraudology , host Karisse Hendrick is joined by Frank McKenna , Chief Fraud Strategist at PointPredictive and the mind behind Frank on Fraud . Frank shares his latest deep dive into Starkiller , a sophisticated new phishing-as-a-service (PaaS) platform that emerged following the takedown of Tycoon 2FA. The conversation explores the terrifying mechanics of Attacker-in-the-Middle (AITM) attacks, where fraudsters use "headless browsers" to mirror legitimate login sessions in real-time. Frank provides an inside look at how this tool allows criminals to capture not just credentials, but also two-factor authentication (2FA) codes and session cookies , enabling them to maintain access even after a user logs out. We also explore the "hot topics" dominating the fraud landscape today: ATO Without a Login Event: How marketplaces are seeing "good" users perform legitimate actions, only to have their payout information changed moments later within the same session. The Democratization of Fraud: The professionalization of phishing kits on Telegram, which offer Netflix-style subscriptions and user-friendly dashboards for as little as $300 to $500 a month . Detection Challenges: Why traditional device intelligence and cybersecurity tools struggle to flag these attacks because the victim is interacting with the real merchant website , not a clone. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/fraudology-podcast-with-karisse-hendrick-1368872/episodes/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/fraudology-podcast-with-karisse-hendrick-1368872/navigating-the-rise-of-starkiller-and-the-future-of-session-hijacking-with-frank-mckenna.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.