When the Session Is the Target: Understanding the Kratos Phishing Kit
- Javier Conejo del Cerro
- hace 1 día
- 2 min de lectura

For years, organizations have encouraged users to create strong passwords and enable multi-factor authentication.
Kratos demonstrates why that is no longer enough.
Rather than breaking authentication, this phishing-as-a-service platform simply waits until authentication succeeds. By stealing the authenticated session instead of only the password, attackers can bypass traditional MFA protections and access Microsoft 365 accounts exactly as the legitimate user.
Phase 1 – A Login Page That Isn’t What It Seems
The attack begins with convincing phishing emails, often themed around taxes or business documents and sometimes delivered through personalized QR codes.
Victims are directed to what appears to be a legitimate Microsoft 365 login page. Behind the scenes, however, a reverse proxy transparently relays every interaction to Microsoft’s real authentication service.
The victim believes they are signing into Microsoft.
They are also signing the attacker in.
Phase 2 – Stealing the Session, Not Just the Password
Unlike traditional phishing kits that only collect usernames and passwords, Kratos captures the authenticated session cookie created after successful login.
Because the victim has already completed MFA, the stolen session allows attackers to access the account without repeating the authentication process.
The security controls work exactly as designed.
The attacker simply reuses the trusted session they produced.
Phase 3 – Turning One Account into Many
Once inside Microsoft 365, attackers gain access as legitimate users.
Compromised mailboxes can be used to launch additional phishing campaigns, impersonate employees, conduct business email compromise (BEC), and expand laterally across the organization’s Microsoft 365 environment.
The stolen session becomes the first step toward a much larger compromise.
Phase 4 – Taking Down the Infrastructure, Not the Threat
Law enforcement dismantled more than 200 servers supporting the Kratos infrastructure and arrested its alleged developer, disrupting one of the world’s largest phishing-as-a-service operations.
However, approximately 1,800 customers had already been using the platform, and many still possess the phishing kit and operational knowledge needed to rebuild similar infrastructure under new names.
The servers disappeared.
The technique did not.
Defense Measures
Organizations should strengthen identity security by:
Deploying phishing-resistant authentication methods.
Revoking active sessions after suspected compromise, not just resetting passwords.
Monitoring anomalous Microsoft 365 sign-ins and session activity.
Educating users about reverse-proxy phishing and QR-code lures.
Detecting known phishing infrastructure indicators.
Applying Conditional Access and continuous identity monitoring.
Identity protection must extend beyond authentication itself.
Conclusions
Kratos reminds us that modern phishing is no longer about stealing passwords.
It is about stealing trust after authentication has already succeeded.
When attackers can inherit an authenticated session, defeating MFA no longer requires breaking security—it only requires standing quietly between the user and the login page.
The safest login is no longer just the one protected by MFA.
It is the one protected against session theft.
The Hacker News




Comentarios