Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
Kratos, the phishing-as-a-Service (PhaaS) platform behind a large share of recent Microsoft 365 credential theft, has been taken offline... Over 1,800 criminal subscribers had purchased access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.
On February 10, operators sent tax-themed emails to about 100 organizations... each carrying a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
Starting with V1... the kit moves to direct brand impersonation, closely replicating the Microsoft Sign In window.
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes.
Kratos gave low-skill cybercriminals a way to steal login credentials such as passwords and email addresses through convincing Microsoft-themed phishing pages.
...harvest Microsoft credentials and tokens in real-time, effectively allowing the threat actors to bypass multi-factor authentication (MFA).
Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts.
It is the direct evolution of Sneaky2FA, an adversary-in-the-middle (AiTM) phishing kit that has targeted Microsoft 365 accounts since October 2024. Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through.
Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through, which is what let the kit defeat MFA rather than just harvest a password.
Kratos gave low-skill cybercriminals a way to steal login credentials such as passwords and email addresses through convincing Microsoft-themed phishing pages.
It is the direct evolution of Sneaky2FA, an adversary-in-the-middle (AiTM) phishing kit that has targeted Microsoft 365 accounts since October 2024. Sneaky2FA relayed live authentication sessions between a victim and Microsoft's real login servers, letting the operator capture both credentials and session tokens as they passed through.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A criminal phishing kit / phishing-as-a-service platform used to steal Microsoft 365 credentials and session cookies. It supports a basic PHP credential-harvesting mode and a Node.js adversary-in-the-middle reverse-proxy mode that relays logins in real time and captures authenticated sessions, enabling bypass of ordinary MFA.
A phishing-as-a-service kit used to harvest credentials, including passwords and session cookies, through convincing Microsoft-themed phishing pages, enabling attackers to bypass multi-factor authentication.
A phishing kit/PhaaS targeting Microsoft 365 users. It impersonates Microsoft login pages, uses anti-bot checks such as Cloudflare Turnstile, steals credentials via PHP endpoints like next.php/save.php/mini.php, and in some cases may support adversary-in-the-middle style session theft or credential relaying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.