Kratos phishing kit infrastructure dismantled to stop Microsoft 365 session theft
Source headline: Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Intelligence Summary
German and US authorities dismantled the core infrastructure behind the Kratos phishing kit. Investigators said Kratos is widely used to steal Microsoft 365 sessions and to help attackers bypass multi-factor authentication. Indonesian authorities also arrested the man they allege developed and ran the kit. The takedown disrupts ongoing credential and session-hijacking campaigns targeting Microsoft cloud accounts. Organizations using Microsoft 365 should review for suspicious login activity and harden MFA and conditional access controls.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.