Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Summary
Law enforcement in Germany and the US have dismantled the Kratos phishing kit, described as one of the most widely used criminal tools for stealing Microsoft 365 sessions and bypassing multi-factor authentication. Indonesian authorities arrested the alleged developer and operator of the kit.
IFF Assessment
FOE
The takedown of a widely used phishing kit represents a win for defenders by disrupting a significant threat infrastructure.
Defender Context
This operation highlights the ongoing threat of sophisticated phishing kits targeting cloud credentials and MFA bypass techniques. Defenders should remain vigilant against such attacks, ensure robust endpoint protection, and educate users on recognizing phishing attempts.