
Phishers Abuse DocuSign, Rewards, and “Verification”
This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…
Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake Microsoft sign-in pages, enabling account takeover and follow-on business email compromise.
Kratos operated as a franchise-style phishing-as-a-service platform. It gave threat actors ready-made toolkits designed to generate convincing Microsoft authentication pages, lowering the technical bar for running credential theft campaigns at scale. Investigators estimate more than 1800 cybercriminals used the platform to launch nearly 15,000 phishing campaigns monthly since late 2024.
A documented campaign from February used tax-themed lures paired with personalized QR codes, targeting manufacturing and healthcare organizations. Victims who scanned the code were routed to a fake Microsoft sign-in page. In its more advanced mode, Kratos used a Node.js reverse proxy to act as an adversary-in-the-middle, intercepting active session cookies in real time. This let attackers bypass standard MFA controls even when a victim completed a normal-looking login.
Several factors combined to make this attack effective:
Defenders and employees should treat certain signals as red flags:
Once an account is compromised, attackers used it as a foothold for business email compromise, lateral data theft, and further phishing inside the organization, so a single successful login can have wide-reaching consequences.
Organizations in manufacturing, healthcare, finance, payroll, and HR should reinforce a few habits across all employees:
The Kratos case shows that phishing kits have matured to the point where MFA bypass is a built-in feature, not an edge case, making user awareness and verification habits an essential complement to technical controls.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Kratos was a phishing-as-a-service platform that provided toolkits for generating convincing Microsoft authentication pages, used by more than 1800 cybercriminals to launch nearly 15,000 phishing campaigns monthly since late 2024.
An advanced Kratos mode deployed a Node.js reverse proxy acting as an adversary-in-the-middle, intercepting active session cookies in real time and effectively bypassing standard MFA controls.
A February campaign used tax-themed lures and personalized QR codes to target American manufacturing and healthcare organizations, directing victims to fake Microsoft sign-in pages.
Compromised accounts gave attackers footholds to carry out business email compromise, lateral data theft, and secondary phishing attacks.
Imagine this email: “Tax-season update: scan your personalized QR code to sign in and review documents.” Looks routine, right? Behind that QR code could be Kratos, a phishing-as-a-service kit. It spins up a perfect-looking Microsoft 365 sign-in, then uses an adversary-in-the-middle proxy to grab your password and even your session cookie, bypassing MFA while your login still looks successful. That’s how February’s Kratos campaigns hit U.S. manufacturing and healthcare: tax-themed emails, personalized QR codes, fake Microsoft auth pages, then business email compromise and invoice fraud from real mailboxes that had MFA turned on. Your move: if any email or QR code sends you to a Microsoft login, stop. Don’t sign in there, close it, and instead open our usual Microsoft 365 portal from your bookmark or company link and sign in only from that trusted path.

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some…

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…