Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
This allowed operators to access the account as an already verified user, meaning a password reset alone might not end the intrusion if active sessions and refresh tokens remain valid.
The campaigns used fake accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.
On February 10, operators sent tax-themed emails to about 100 organizations... each carrying a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login.
Starting with V1... the kit moves to direct brand impersonation, closely replicating the Microsoft Sign In window.
Kratos gave low-skill cybercriminals a way to steal login credentials such as passwords and email addresses through convincing Microsoft-themed phishing pages.
использовалась для кражи аккаунтов Microsoft 365 и обхода многофакторной аутентификации
When a user entered credentials and completed multi-factor authentication, the kit relayed the live session and collected the authentication token.
В первом использовалась обычная PHP-страница, которая собирала логины и пароли жертв
By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in AiTM phishing attack methods that can weaken the protection offered by multi-factor authentication.
Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through, which is what let the kit defeat MFA rather than just harvest a password.
Kratos gave low-skill cybercriminals a way to steal login credentials such as passwords and email addresses through convincing Microsoft-themed phishing pages.
Attackers with Microsoft 365 access may read business conversations...
Monitoring mailbox rules is also important because compromised accounts can be used to quietly redirect financial messages or hide security alerts...
By placing itself between the victim and Microsoft’s real authentication system, Kratos could capture passwords and active session tokens, a technique also seen in AiTM phishing attack methods that can weaken the protection offered by multi-factor authentication.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing platform referenced as an alternative destination in some of the malicious PDF lures used in the campaign.
A phishing-as-a-service platform that uses trusted cloud redirects and DocuSign-style lures to drive Microsoft 365 users to credential-harvesting pages.
A phishing-as-a-service platform used to steal Microsoft 365 credentials and active session tokens at scale. It uses adversary-in-the-middle phishing techniques, fake Microsoft sign-in pages, anti-bot checks, CAPTCHA/browser screening, and automated exfiltration of stolen data to enable account takeover even after MFA completion.
A criminal phishing kit / phishing-as-a-service platform used to steal Microsoft 365 credentials and session cookies. It supports a basic PHP credential-harvesting mode and a Node.js adversary-in-the-middle reverse-proxy mode that relays logins in real time and captures authenticated sessions, enabling bypass of ordinary MFA.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.