Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

July 22, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Microsoft 365 users across global enterprises
Incident: Dismantling of the Kratos/SneakyLog phishing-as-a-service infrastructure.
Impact: Hundreds of thousands of accounts compromised via session hijacking and MFA bypass.
Attacker: Kratos/SneakyLog developers and affiliate customers
Analysis: The Kratos kit leveraged an Adversary-in-the-Middle (AiTM) approach, utilizing a reverse proxy to capture session cookies in real-time. By stealing these cookies, attackers could bypass traditional MFA, gaining direct access to corporate Microsoft 365 environments. While the core servers are offline, the distributed nature of its ‘franchise’ model means the kit’s code may still be utilized by previous subscribers.
Recommendations: Implement phishing-resistant MFA such as FIDO2 or passkeys; Monitor for anomalous session cookie usage and unexpected login locations; Educate users on identifying QR-code-based phishing (Quishing) attempts
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *