Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. By combining trusted platforms, anti-bot checks, and convincing login pages, ithelps attackers steal credentials while delaying detection and response. For security leaders, that increases the risk of account takeover, fraud, data exposure, and higher incident response costs.
ANY.RUN researchers traced three generations of the kit, uncovered 1,484 previously unattributed detonations, and mapped its infrastructure, operator panel, and victim patterns. This article gives security teams practical fingerprints, exfiltration indicators, SIEM scoring rules, and response guidance to reduce exposure, speed up investigations, and make faster decisions when Kratos activity appears.
Key Takeaways
- Kratos is a turnkey phishing kit built to steal Microsoft 365 credentials and sold through a subscription model. Operator-side intelligence, including its admin panel and automated deployment features, shows that it operates as a full Phishing-as-a-Service (PhaaS) platform.
- ANY.RUN researchers identified 1,628 sandbox...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE