hacker-news · Crawled Jul 22, 2026

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

4 IoCs
Read original article ↗

AI Summary

Law enforcement from Germany, the U.S., and Indonesia dismantled the Kratos phishing-as-a-service platform, which was used to steal Microsoft 365 session cookies and bypass multi-factor authentication (MFA). The platform enabled low-skill attackers to launch phishing campaigns via a franchise-like model, resulting in hundreds of thousands of victims across over 30 countries since late 2024. Kratos operated using an adversary-in-the-middle (AiTM) technique that captured live sessions, allowing attackers to bypass MFA by stealing session cookies. The takedown disrupted over 200 servers, but the customer base and existing kit code remain a persistent threat.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Filename next.php Details →
Filename save.php Details →
Filename barr.svg Details →
Filename lg.svg Details →