Crypto Ticker:
sysadmin from Cyber Security News

Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users

Tushar Subhra Dutta
Tuesday at 12:42
12 Views
0 Comments
Dismantled Kratos Phishing Kits Acting as Blueprint for Others to Attack Microsoft 365 Users

Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login pages, hosting options, and evasion features that made fraudulent sign-ins harder to detect. The operation relied on phishing emails that led targets through trusted-looking services before showing a fake login page. By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in AiTM phishing attack methods that can weaken the protection offered by multi-factor authentication. Analysts at ANY.RUN identified Kratos as a mature Phishing-as-a-Service platform with a dashboard,...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!