Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

Kratos phishing kit dismantled; session cookie theft bypasses MFA

Law enforcement dismantled the Kratos phishing infrastructure, which bypassed MFA by stealing Microsoft 365 session cookies. While the primary operator was arrested in Indonesia and 200 servers were seized, approximately 1,800 customers retain access to the malicious code, posing a persistent threat.

The Hacker News1 day agoIDCredibility 54%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.5

Intelligence Tags

Locations

Indonesia

Entities

country
Source

Related signals

8 found