hacker-news · Crawled Jul 22, 2026
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
4 IoCs
Read original article ↗
AI Summary
Law enforcement from Germany, the U.S., and Indonesia dismantled the Kratos phishing-as-a-service platform, which was used to steal Microsoft 365 session cookies and bypass multi-factor authentication (MFA). The platform enabled low-skill attackers to launch phishing campaigns via a franchise-like model, resulting in hundreds of thousands of victims across over 30 countries since late 2024. Kratos operated using an adversary-in-the-middle (AiTM) technique that captured live sessions, allowing attackers to bypass MFA by stealing session cookies. The takedown disrupted over 200 servers, but the customer base and existing kit code remain a persistent threat.
AI-extracted · verify before operational use