Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users

Tushar Subhra Dutta
Tuesday at 12:42
11 Visninger
0 Kommentarer
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users

Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login pages, hosting options, and evasion features that made fraudulent sign-ins harder to detect. The operation relied on phishing emails that led targets through trusted-looking services before showing a fake login page. By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in AiTM phishing attack methods that can weaken the protection offered by multi-factor authentication. Analysts at ANY.RUN identified Kratos as a mature Phishing-as-a-Service platform with a dashboard,...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!