HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Law Enforcement Dismantles Kratos Phishing Kit Targeting Microsoft 365 Sessions and Bypassing MFA

German and U.S. authorities have taken down Kratos, a phishing kit that harvests Microsoft 365 authentication cookies and can bypass MFA, highlighting the need for strong access‑control and security‑awareness programs. The takedown underscores why SOC 2 auditors look for documented MFA enforcement and training evidence.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Law Enforcement Dismantles Kratos Phishing Kit Targeting Microsoft 365 Sessions and Bypassing MFA

What Happened — German and U.S. authorities seized the infrastructure behind Kratos, a phishing kit that harvests Microsoft 365 authentication cookies and can bypass multi‑factor authentication (MFA). The operation also led to the arrest of the individual who built and operated the kit in Indonesia.

Why It Matters for Compliance & Audit Readiness

  • The kit demonstrates how credential‑theft attacks can defeat MFA, a control directly addressed by SOC 2 CC6.1 (Logical Access) and CC6.2 (Multi‑Factor Authentication).
  • Continuous evidence of security‑awareness training and robust access‑control policies is essential to show auditors that your organization can detect and respond to credential‑phishing attempts.
  • Verisq’s Security Awareness capability provides automated training metrics and phishing‑simulation evidence that can be attached to a SOC 2 audit as proof of control effectiveness.

Who Is Affected – Enterprises that rely on Microsoft 365 or other cloud productivity suites, spanning technology, finance, healthcare, and government sectors.

Recommended Actions

  • Review and tighten MFA enforcement (e.g., require hardware tokens, conditional access policies).
  • Conduct a phishing‑simulation campaign and update security‑awareness training to cover session‑hijacking techniques.
  • Map the incident to SOC 2 CC6.1/CC6.2 controls, collect training completion logs, and retain simulation results as audit evidence.

Technical Notes – Kratos uses malicious links that lure victims into entering their Microsoft 365 credentials, then captures authentication cookies via a hidden iframe. The stolen cookies grant attackers persistent access, effectively sidestepping MFA. No specific CVE is involved; the threat relies on social engineering and session‑hijacking. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →