Kratos PhaaS Fueled MFA-Bypass Phishing

SentinelOne · High sophistication
Last updated July 30, 2026

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake Microsoft sign-in pages, enabling account takeover and follow-on business email compromise.

How the attack worked

Kratos operated as a franchise-style phishing-as-a-service platform. It gave threat actors ready-made toolkits designed to generate convincing Microsoft authentication pages, lowering the technical bar for running credential theft campaigns at scale. Investigators estimate more than 1800 cybercriminals used the platform to launch nearly 15,000 phishing campaigns monthly since late 2024.

A documented campaign from February used tax-themed lures paired with personalized QR codes, targeting manufacturing and healthcare organizations. Victims who scanned the code were routed to a fake Microsoft sign-in page. In its more advanced mode, Kratos used a Node.js reverse proxy to act as an adversary-in-the-middle, intercepting active session cookies in real time. This let attackers bypass standard MFA controls even when a victim completed a normal-looking login.

Why it succeeded

Several factors combined to make this attack effective:

  • QR codes obscure the true destination URL, making it harder for recipients to spot a lookalike domain before scanning
  • Seasonal tax-related urgency pushed recipients to act quickly rather than verify the request
  • The authentication pages closely mimicked genuine Microsoft sign-in screens, so the login flow felt normal
  • Session cookie theft meant that even successful MFA completion did not stop the compromise

What to watch for

Defenders and employees should treat certain signals as red flags:

  • Unsolicited messages asking to scan a QR code to "review documents" or sign in
  • Sign-in prompts tied to tax season or other seasonal deadlines that create urgency
  • A Microsoft-branded login page reached through a link or QR code rather than a bookmark or known company portal
  • Unusual account activity following a sign-in event, which may indicate a stolen session rather than just stolen credentials

Once an account is compromised, attackers used it as a foothold for business email compromise, lateral data theft, and further phishing inside the organization, so a single successful login can have wide-reaching consequences.

How to build resistance

Organizations in manufacturing, healthcare, finance, payroll, and HR should reinforce a few habits across all employees:

  • Treat QR-code based sign-in requests as high risk and verify the destination through a trusted path, such as a bookmark or known internal portal, before entering credentials
  • Recognize that MFA alone does not stop session cookie theft; phishing-resistant MFA methods reduce this risk
  • Train staff to recognize convincing but fake Microsoft sign-in pages, especially those reached via email links or QR codes
  • Encourage immediate reporting of unexpected sign-in prompts so security teams can respond before a stolen session is used for BEC or further phishing

The Kratos case shows that phishing kits have matured to the point where MFA bypass is a built-in feature, not an edge case, making user awareness and verification habits an essential complement to technical controls.

Key findings

  • Law enforcement seized “over 200 servers” during “Operation Olympus Blade,” dismantling the Kratos phishing-as-a-service infrastructure and arresting the suspected developer in Indonesia.
  • Investigators estimate “more than 1800 cybercriminals utilized the platform to launch nearly 15,000 phishing campaigns monthly since late 2024.”
  • Kratos provided “toolkits designed to generate convincing Microsoft authentication pages,” enabling credential theft and unauthorized access.
  • A more advanced Kratos mode used an “adversary-in-the-middle (AitM)” Node.js reverse proxy to “intercept active session cookies in real-time,” effectively bypassing MFA.
  • Compromised accounts were then used for “business email compromise (BEC), lateral data theft, and secondary phishing attacks.”
  • A documented February campaign used “tax-themed lures and personalized QR codes” targeting “American manufacturing and healthcare organizations.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Payroll, HR, Executives, IT Helpdesk.
  • Affected industries: Manufacturing, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft login / Microsoft 365 sign-in, Microsoft authentication / Microsoft 365.

Red flags to watch for

  • Uses a QR code to hide the true destination URL
  • Urgent/seasonal tax pressure to act quickly
  • Sign-in page looks like Microsoft but is not reached through a normal company process/bookmark
  • Unexpected sign-in demand not tied to a known task
  • Link leads to a lookalike login experience
  • Login completes, but attacker can still access the account (session cookie theft)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the Kratos phishing-as-a-service platform?

Kratos was a phishing-as-a-service platform that provided toolkits for generating convincing Microsoft authentication pages, used by more than 1800 cybercriminals to launch nearly 15,000 phishing campaigns monthly since late 2024.

How did Kratos bypass multi-factor authentication?

An advanced Kratos mode deployed a Node.js reverse proxy acting as an adversary-in-the-middle, intercepting active session cookies in real time and effectively bypassing standard MFA controls.

How were QR codes used in this attack?

A February campaign used tax-themed lures and personalized QR codes to target American manufacturing and healthcare organizations, directing victims to fake Microsoft sign-in pages.

What happened after accounts were compromised?

Compromised accounts gave attackers footholds to carry out business email compromise, lateral data theft, and secondary phishing attacks.

Read the video transcript

Imagine this email: “Tax-season update: scan your personalized QR code to sign in and review documents.” Looks routine, right? Behind that QR code could be Kratos, a phishing-as-a-service kit. It spins up a perfect-looking Microsoft 365 sign-in, then uses an adversary-in-the-middle proxy to grab your password and even your session cookie, bypassing MFA while your login still looks successful. That’s how February’s Kratos campaigns hit U.S. manufacturing and healthcare: tax-themed emails, personalized QR codes, fake Microsoft auth pages, then business email compromise and invoice fraud from real mailboxes that had MFA turned on. Your move: if any email or QR code sends you to a Microsoft login, stop. Don’t sign in there, close it, and instead open our usual Microsoft 365 portal from your bookmark or company link and sign in only from that trusted path.

Similar attacks

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Kratos Kit Used W-2 QR Phish to Hijack M365

Kratos Kit Used W-2 QR Phish to Hijack M365

Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some cases, capture session cookies to bypass MFA. The article describes a real, observed campaign using tax-themed W-2 QR-code emails that led…

July 22, 2026