Kratos Phishing Kit Dismantled: Microsoft 365 Session Theft and MFA Bypass Operation Analysis

Kratos Phishing Kit Dismantled: Microsoft 365 Session Theft and MFA Bypass Operation Analysis

Executive Summary

Publication Date: June 2026

Law enforcement agencies have successfully dismantled the core infrastructure behind the Kratos phishing kit, a sophisticated phishing-as-a-service (PhaaS) platform engineered to steal Microsoft 365 credentials and session cookies. This operation, led by German authorities with support from the United States and Indonesia, neutralized over 200 servers and resulted in the arrest of the alleged developer and technical administrator. The Kratos kit enabled cybercriminals to bypass multi-factor authentication (MFA) and gain persistent access to corporate accounts, fueling a surge in credential theft and post-compromise exploitation across more than 35 countries. This report provides a comprehensive analysis of the technical, operational, and security implications of Kratos, as well as guidance for defenders and insights into the evolving threat landscape.

Introduction

The takedown of the Kratos phishing kit marks a significant milestone in the fight against advanced phishing threats targeting cloud-based enterprise environments. Kratos distinguished itself through its use of legitimate cloud services, advanced evasion techniques, and a scalable affiliate model, making it one of the most effective and widely adopted phishing platforms in recent years. This report examines the technical architecture, operational impact, and security challenges posed by Kratos, offering actionable recommendations for organizations seeking to defend against similar threats.

Technical Analysis of the Kratos Phishing Kit

The Kratos phishing kit is a highly modular and adaptable platform designed to facilitate large-scale credential theft from Microsoft 365 users. Its core functionality centers on the creation of convincing fake login pages that mimic legitimate Microsoft 365 authentication flows. Attackers leverage real SharePoint, OneDrive, Canva, Tilda, and Microsoft Forms links as intermediary hops, making phishing URLs appear authentic and difficult to detect. The kit employs Cloudflare Turnstile and other CAPTCHA services to evade automated analysis and security sandboxes.

A key innovation of Kratos is its ability to steal both credentials and session cookies, enabling attackers to bypass MFA and maintain persistent access to compromised accounts. Exfiltration is achieved through attacker-controlled endpoints, such as next.php and save.php, with stolen data delivered via Telegram bots or email. The kit’s unique asset fingerprinting—specifically the paired use of barr.svg and lg.svg files—provides a rare detection opportunity, as this combination appears in the vast majority of Kratos sessions.

The Kratos admin panel empowers affiliates to deploy phishing domains, upload files, install TLS certificates, modify DNS settings, apply country whitelists, and select anti-bot measures. This operational flexibility supports rapid campaign deployment and high-volume attacks, with more than 1,800 criminal groups launching approximately 15,000 phishing campaigns each month across over 30 countries.

Security Implications and Risks

The security risks associated with Kratos are profound. By stealing session cookies, attackers can bypass MFA protections, rendering password resets ineffective unless all active sessions are revoked. Compromised accounts are often used for invoice fraud, payment redirection, and unauthorized access to sensitive data stored in SharePoint and OneDrive. The impact of a single compromised mailbox can cascade throughout an organization, exposing additional accounts and resources.

Kratos campaigns have targeted a wide range of sectors, including financial services, healthcare, education, retail, manufacturing, technology, law firms, and small to medium-sized businesses. The use of legitimate cloud services and compromised infrastructure complicates detection and remediation, increasing the risk of supply chain compromise and persistent threats.

Supply Chain and Third-Party Dependencies

Kratos exploits trusted cloud services and third-party platforms to deliver phishing payloads and evade security controls. Campaigns have impersonated services such as SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and Adobe, utilizing evasive delivery methods like QR codes, OneNote and Excel attachments, URL shorteners, cloud-hosted pages, and bot filtering. The kit is frequently hosted on compromised WordPress sites, further increasing the risk of supply chain compromise and complicating takedown efforts.

Security Controls and Compliance Requirements

To defend against threats like Kratos, organizations should implement advanced monitoring for requests to unique asset pairs (such as barr.svg and lg.svg) and suspicious POST requests to known exfiltration endpoints. The presence of CAPTCHA or Turnstile checks in front of Microsoft login pages should be treated as a red flag. If credentials are suspected to have been compromised, it is critical to revoke all sessions and refresh tokens, not just reset passwords. Additional measures include auditing inbox rules, OAuth grants, and SharePoint access.

Security best practices recommend reducing device-registration limits in Microsoft Entra ID from the default value of 50 to one or two, blocking device code authentication, and regularly auditing app registrations. These controls help limit the impact of account hijack incidents and reduce response and remediation times.

Industry Adoption and Integration Challenges

The widespread adoption of Kratos by cybercriminals is driven by its ease of use, scalability, and effectiveness. Investigators estimate that more than 1,800 criminal groups have used the kit to launch approximately 15,000 phishing campaigns per month, primarily targeting organizations in the US and Europe. The use of legitimate cloud services and compromised infrastructure makes detection and remediation particularly challenging for defenders, highlighting the need for continuous monitoring and rapid incident response capabilities.

Vendor Security Practices and Track Record

While Kratos itself is a criminal service, its abuse of legitimate platforms underscores the importance of robust vendor security practices. Vendors must enhance detection of suspicious OAuth flows and device registrations, improve monitoring for anomalous use of cloud services, and collaborate with law enforcement and industry partners for rapid takedown and intelligence sharing. Proactive engagement with the security community is essential to mitigate the risks posed by advanced phishing kits.

Technical Specifications

Kratos phishing pages are typically PHP-based and require hosting on compromised or attacker-controlled servers. The kit supports integration with Telegram bots and email for exfiltration, and affiliates can deploy campaigns via a web-based admin panel with options for TLS, DNS, and anti-bot configuration. Compatibility with a wide range of cloud services allows Kratos to be rapidly adapted to new lures and delivery methods, increasing its operational flexibility and threat potential.

Cyber Perspective

From a cyber defense perspective, Kratos exemplifies a new generation of phishing-as-a-service platforms that combine technical sophistication with operational scalability. Attackers can now bypass MFA and gain persistent access to cloud accounts, rendering traditional security controls less effective. The exploitation of legitimate cloud services and compromised infrastructure increases the risk of supply chain compromise and complicates detection and response efforts. Defenders must adopt advanced monitoring, rapid session revocation, and proactive threat hunting to counter these evolving threats.

For attackers, Kratos lowers the barrier to entry for large-scale credential theft and post-compromise exploitation, fueling a growing cybercrime ecosystem and increasing the risk to organizations of all sizes. The dismantling of the Kratos infrastructure is a significant victory for law enforcement, but the underlying techniques and operational models are likely to persist and evolve, necessitating ongoing vigilance and adaptation by defenders.

About Rescana

Rescana’s Third-Party Risk Management (TPRM) solutions empower organizations to identify, assess, and mitigate risks arising from supply chain and third-party dependencies—including those exploited by advanced phishing kits. Our platform delivers continuous monitoring, automated risk assessments, and actionable intelligence to help you stay ahead of emerging threats. With Rescana, you can strengthen your vendor risk posture, ensure compliance, and respond rapidly to incidents affecting your extended enterprise.

We are happy to answer your questions at info@rescana.com.