Law Enforcement Dismantles Kratos Phishing Kit Targeting Microsoft 365 Sessions and Bypassing MFA
What Happened — German and U.S. authorities seized the infrastructure behind Kratos, a phishing kit that harvests Microsoft 365 authentication cookies and can bypass multi‑factor authentication (MFA). The operation also led to the arrest of the individual who built and operated the kit in Indonesia.
Why It Matters for Compliance & Audit Readiness
- The kit demonstrates how credential‑theft attacks can defeat MFA, a control directly addressed by SOC 2 CC6.1 (Logical Access) and CC6.2 (Multi‑Factor Authentication).
- Continuous evidence of security‑awareness training and robust access‑control policies is essential to show auditors that your organization can detect and respond to credential‑phishing attempts.
- Verisq’s Security Awareness capability provides automated training metrics and phishing‑simulation evidence that can be attached to a SOC 2 audit as proof of control effectiveness.
Who Is Affected – Enterprises that rely on Microsoft 365 or other cloud productivity suites, spanning technology, finance, healthcare, and government sectors.
Recommended Actions
- Review and tighten MFA enforcement (e.g., require hardware tokens, conditional access policies).
- Conduct a phishing‑simulation campaign and update security‑awareness training to cover session‑hijacking techniques.
- Map the incident to SOC 2 CC6.1/CC6.2 controls, collect training completion logs, and retain simulation results as audit evidence.
Technical Notes – Kratos uses malicious links that lure victims into entering their Microsoft 365 credentials, then captures authentication cookies via a hidden iframe. The stolen cookies grant attackers persistent access, effectively sidestepping MFA. No specific CVE is involved; the threat relies on social engineering and session‑hijacking. Source: The Hacker News