Kratos is a phishing service built to steal Microsoft 365 credentials at scale. It evolved from the Sneaky2FA kit and gave affiliates ready-made login pages, hosting options, and evasion features that made fraudulent sign-ins harder to detect. The operation relied on phishing emails that led targets through trusted-looking services before showing a fake login page. By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in AiTM phishing attack methods that can weaken the protection offered by multi-factor authentication. Analysts at ANY.RUN identified Kratos as a mature Phishing-as-a-Service platform with a dashboard,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!