Kratos Phishing Kit Takedown Disrupts Microsoft 365 MFA Bypass Campaigns
International law enforcement has dismantled the infrastructure behind the Kratos phishing kit, a phishing-as-a-service (PhaaS) platform used to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA). Authorities seized over 200 servers and arrested the alleged developer, disrupting thousands of phishing campaigns targeting organizations worldwide.


Kratos used adversary-in-the-middle (AiTM) techniques to capture both user credentials and active Microsoft 365 session cookies, allowing attackers to bypass MFA and gain unauthorized account access. The phishing kit was widely used to launch business email compromise (BEC) attacks and steal sensitive enterprise data.
Organizations should enforce phishing-resistant MFA, revoke compromised sessions, monitor suspicious login activity, and train employees to recognize phishing attempts. Strong identity protection and continuous threat monitoring remain essential to defend against advanced phishing campaigns.
NPAV Endpoint Security, help detect fileless malware, block malicious scripts, and protect users from credential-stealing attacks delivered through fake software downloads.