Kratos Phishing Kits Target Microsoft 365 Users
Key Takeaways A new phishing kit, dubbed “Kratos,” is actively targeting Microsoft 365 users. Kratos operates by mimicking legitimate Microsoft 365 login pages to steal credentials. The...
Key Takeaways
- A new phishing kit, dubbed “Kratos,” is actively targeting Microsoft 365 users.
- Kratos operates by mimicking legitimate Microsoft 365 login pages to steal credentials.
- The kit incorporates sophisticated evasion techniques, including IP-based filtering and the use of legitimate SharePoint domains.
- Organizations should implement strong authentication, monitor mailbox rules, and revoke sessions after suspected compromise.
Kratos Phishing Kits Emerge as New Threat to Microsoft 365 Users
A sophisticated new phishing kit, identified as “Kratos,” is actively being deployed to compromise Microsoft 365 user accounts. This kit is designed to replicate authentic Microsoft login interfaces, tricking unsuspecting users into divulging their credentials. Security researchers have detailed the technical intricacies of Kratos, highlighting its advanced evasion capabilities and modular design, which could serve as a template for future phishing campaigns.
Table Of Content
Operational Mechanics of Kratos
The Kratos phishing kit demonstrates a notable level of sophistication in its operational tactics. It leverages IP-based filtering to evade detection by security researchers and automated scanners, ensuring that the malicious pages are only served to intended victims. Furthermore, the kit utilizes legitimate SharePoint domains, such as ttressoluciones-my.sharepoint.com and grupohuertassa-my.sharepoint.com, to host its phishing pages, lending an air of authenticity to the attacks and making them harder to distinguish from legitimate Microsoft communications. This approach significantly enhances the kit’s ability to bypass traditional email filters and user scrutiny.
Upon a successful compromise, Kratos enables threat actors to gain unauthorized access to Microsoft 365 accounts. This access can be exploited for various malicious purposes, including data exfiltration, business email compromise (BEC) scams, and further propagation of phishing attacks within an organization. The modular nature of Kratos, with distinct versions (V0, V1, V2) utilizing different data submission endpoints like mini.php, next.php, and save.php, suggests an ongoing development effort to refine its capabilities and adapt to new security measures.
Indicators of Compromise (IoCs) and Mitigation Strategies
Security analysts have identified several Indicators of Compromise (IoCs) associated with Kratos phishing campaigns. These include specific domains such as eimex.com.mx and generlabeton.info, along with various file names like barr.svg, lg.svg, and dsa.svg, which serve as family-identification assets for the kit. The kit also employs geoplugin.net for victim geolocation and filtering, further illustrating its targeted approach. Hashes for key assets, such as c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb for lg.svg and cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea for styles.css, have also been documented. A comprehensive report detailing the technical analysis and IoCs is available here, which also includes a note on defanging IP addresses and domains to prevent accidental resolution.
What You Should Do
- Implement Multi-Factor Authentication (MFA): Mandate phishing-resistant MFA across all Microsoft 365 accounts to significantly reduce the risk of credential compromise.
- Monitor Mailbox Rules: Regularly audit and monitor mailbox rules for any unauthorized changes that could indicate a compromised account being used to redirect emails or hide security alerts.
- Revoke Sessions and Refresh Tokens: In the event of a suspected account takeover, immediately initiate password resets and revoke all active sessions and refresh tokens for the affected user.
- Apply Conditional Access Policies: Utilize conditional access controls to restrict access based on user location, device compliance, and other contextual factors.
- Review Web
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.