Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker then reuses these cookies to open authenticated sessions, bypassing MFA and gaining full visibility into Outlook mailboxes, SharePoint files, and broader Microsoft 365 resources.
Following the first wave of phishing emails, the attacker leveraged one of the newly compromised M365 accounts ... and sent a second wave of phishing emails out from the user’s email address.
This campaign begins with emails sent from compromised organizational accounts, a tactic used to lend credibility to the lures. The emails themselves are themed around professional workflows: requests for information (RFIs), formal bid invitations, and shared project documentation.
The first layer abuses KrakVM, an open-source JavaScript virtual machine that compiles its payload into encrypted bytecode, making the malicious content invisible to tools that inspect the attachment without executing it.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
Visitors to the URL would be routed to a counterfeit Microsoft login page. That page captured credentials and multifactor authentication tokens and sent them via an HTTP POST message to an adversary-controlled “backend server” page.
These include compromised credentials, brute-force attempts, and phishing, along with less common approaches such as trusted relationships in which privileged credentials were over-privileged, or in which access was gained by theft of an authentication token.
Since attackers are harvesting session cookies and tokens, they inherit fully authenticated identities inside Microsoft 365 rather than simply stealing passwords.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time...
The attack flow begins with an HTTP POST transmission to a C2 server stored as a URL Base64 encoded within the script... It first sends a simple do=user-check... If so, another HTTP POST sends the initial information as do=check&email=<victim_email>.
That page captured credentials and multifactor authentication tokens and sent them via an HTTP POST message to an adversary-controlled “backend server” page —a PHP page with a seemingly random number for its name... In this case, the same URL to send an authentication request for the target as used in communication requests to the “backend portal”—in this case, to a backend server utilizing the file “next.php”.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing-as-a-service kit used to harvest credentials and intercept MFA-protected sessions by reverse-proxying Microsoft authentication workflows. The content says it mainly targets Microsoft 365 credentials and may be a rebrand of Rockstar2FA.
Mentioned only as another AiTM phishing kit sharing hosting infrastructure with Kratos.
A phishing-as-a-service credential harvesting kit used to steal credentials for Microsoft 365 and other providers, with support for adversary-in-the-middle MFA interception and targeted fake login pages guided by C2 responses.
A synchronous-replay adversary-in-the-middle phishing kit used to capture victim credentials and MFA tokens, then rapidly replay them to establish authenticated sessions and enable account compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.