Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
ID: 4208c55d-42b1-5e16-886c-46666d32c9a6
STIX ID: report--4208c55d-42b1-5e16-886c-46666d32c9a6
Feed Name: The Hacker News
German and U.S. authorities dismantled the core infrastructure of Kratos (aka SneakyLog), a widely used phishing-as-a-service AiTM kit that harvested credentials and session cookies to bypass MFA; investigators found ~1,800 paying customers running ~15,000 phishing campaigns monthly and hundreds of thousands of victims across 30+ countries, and while servers were taken offline the customers and kit code remain a continuing risk. Defenders can hunt for telltale assets (barr.svg, lg.svg) and endpoints (next.php, save.php), and remediation depends on whether sessions were stolen (revocation required) or only credentials captured (password reset and MFA checks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
