Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Origin Confirms Data Breach Exposing 900,000 Customer Records
July 28, 2026
Critical Apache Shiro RCE Vulnerability Under Active Exploitation
July 28, 2026
Google Ads Push MacSync Infostealer via Fake Claude Install Guides
July 28, 2026
Home/Threats/Kratos Phishing Kits Target Microsoft 365 Users
Threats

Kratos Phishing Kits Target Microsoft 365 Users

Key Takeaways A new phishing kit, dubbed “Kratos,” is actively targeting Microsoft 365 users. Kratos operates by mimicking legitimate Microsoft 365 login pages to steal credentials. The...

Emy Elsamnoudy
Emy Elsamnoudy
July 28, 2026 3 Min Read
2 0

Key Takeaways

  • A new phishing kit, dubbed “Kratos,” is actively targeting Microsoft 365 users.
  • Kratos operates by mimicking legitimate Microsoft 365 login pages to steal credentials.
  • The kit incorporates sophisticated evasion techniques, including IP-based filtering and the use of legitimate SharePoint domains.
  • Organizations should implement strong authentication, monitor mailbox rules, and revoke sessions after suspected compromise.

Kratos Phishing Kits Emerge as New Threat to Microsoft 365 Users

A sophisticated new phishing kit, identified as “Kratos,” is actively being deployed to compromise Microsoft 365 user accounts. This kit is designed to replicate authentic Microsoft login interfaces, tricking unsuspecting users into divulging their credentials. Security researchers have detailed the technical intricacies of Kratos, highlighting its advanced evasion capabilities and modular design, which could serve as a template for future phishing campaigns.

Table Of Content

  • Key Takeaways
  • Kratos Phishing Kits Emerge as New Threat to Microsoft 365 Users
  • Operational Mechanics of Kratos
  • Indicators of Compromise (IoCs) and Mitigation Strategies
  • What You Should Do

Operational Mechanics of Kratos

The Kratos phishing kit demonstrates a notable level of sophistication in its operational tactics. It leverages IP-based filtering to evade detection by security researchers and automated scanners, ensuring that the malicious pages are only served to intended victims. Furthermore, the kit utilizes legitimate SharePoint domains, such as ttressoluciones-my.sharepoint.com and grupohuertassa-my.sharepoint.com, to host its phishing pages, lending an air of authenticity to the attacks and making them harder to distinguish from legitimate Microsoft communications. This approach significantly enhances the kit’s ability to bypass traditional email filters and user scrutiny.

Upon a successful compromise, Kratos enables threat actors to gain unauthorized access to Microsoft 365 accounts. This access can be exploited for various malicious purposes, including data exfiltration, business email compromise (BEC) scams, and further propagation of phishing attacks within an organization. The modular nature of Kratos, with distinct versions (V0, V1, V2) utilizing different data submission endpoints like mini.php, next.php, and save.php, suggests an ongoing development effort to refine its capabilities and adapt to new security measures.

Indicators of Compromise (IoCs) and Mitigation Strategies

Security analysts have identified several Indicators of Compromise (IoCs) associated with Kratos phishing campaigns. These include specific domains such as eimex.com.mx and generlabeton.info, along with various file names like barr.svg, lg.svg, and dsa.svg, which serve as family-identification assets for the kit. The kit also employs geoplugin.net for victim geolocation and filtering, further illustrating its targeted approach. Hashes for key assets, such as c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb for lg.svg and cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea for styles.css, have also been documented. A comprehensive report detailing the technical analysis and IoCs is available here, which also includes a note on defanging IP addresses and domains to prevent accidental resolution.

What You Should Do

  • Implement Multi-Factor Authentication (MFA): Mandate phishing-resistant MFA across all Microsoft 365 accounts to significantly reduce the risk of credential compromise.
  • Monitor Mailbox Rules: Regularly audit and monitor mailbox rules for any unauthorized changes that could indicate a compromised account being used to redirect emails or hide security alerts.
  • Revoke Sessions and Refresh Tokens: In the event of a suspected account takeover, immediately initiate password resets and revoke all active sessions and refresh tokens for the affected user.
  • Apply Conditional Access Policies: Utilize conditional access controls to restrict access based on user location, device compliance, and other contextual factors.
  • Review Web

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    phishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Fake Crypto Wallet Scams Steal Seed Phrases and Browser Sessions

Next Post

Google Ads Push MacSync Infostealer via Fake Claude Install Guides

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI-Assisted Research Finds Linux Kernel Zero-Day for Root Escalation
July 28, 2026
GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
July 28, 2026
Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us