Kratos: a blow to Microsoft 365 phishing and MFA bypass

Colleagues, here is a cybersecurity update worth noting: law enforcement in Germany and the U.S. has taken down the Kratos infrastructure, one of the most widely used phishing kits targeting Microsoft 365.
More than 200 servers were shut down, and a suspect believed to be the scheme’s developer and operator was arrested in Indonesia.
Kratos was dangerous not only because it stole credentials. In reverse-proxy mode, it intercepted session cookies, enabling MFA bypass and account access as the legitimate user.
Scale: around 1,800 customers and up to 15,000 campaigns per month.
Why it matters: even with MFA, an attack can end in session hijacking, followed by phishing, email compromise, and Microsoft 365 access.
How do you protect sessions and spot AiTM attack indicators? #cybersecurity #phishing #Microsoft365 #MFA


Latest comments
No comments yet.