← BACK TO FEED
TAG

microsoft 3652 articles

Kratos Phishing Kit Dismantled: 200 Servers Down, But 1,800 Customers Still Have the Code

German and US authorities, alongside Indonesian police, have dismantled Kratos, a major phishing-as-a-service platform that enabled around 1,800 criminal customers to run approximately 15,000 phishing campaigns per month, taking more than 200 servers offline and arresting its alleged developer. The kit was particularly dangerous due to its adversary-in-the-middle capability, which stole live Microsoft 365 session cookies alongside credentials, allowing attackers to bypass multi-factor authentication entirely. However, the takedown leaves the kit's existing customer base and their copies of the code untouched, raising concerns that similar operations could resurface under a new name.

23 Jul 2026

EvilTokens Phishing Kit Is Far Nastier Than Anyone Realised

EvilTokens, a device-code phishing kit capable of bypassing multi-factor authentication on Microsoft 365, has been found to be more sophisticated than previously understood, with Cisco Talos uncovering a linked phishing-as-a-service operator panel called "ARToken." Talos revealed how the phishing lures reach victims' inboxes, describing a targeted approach that exploits real vendor relationships and abuses legitimate SharePoint domains to evade detection. Beyond simple credential theft, ARToken includes a comprehensive post-exploitation toolkit with full business email compromise capabilities, making it a complete BEC operations platform rather than just a phishing kit.

6 Jul 2026