Kratos PhaaS Fueled MFA-Bypass Phishing

SentinelOne · High sophistication
Last updated July 30, 2026

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake Microsoft sign-in pages, enabling account takeover and follow-on business email compromise.

How the attack worked

Kratos operated as a franchise-style phishing-as-a-service platform. It gave threat actors ready-made toolkits designed to generate convincing Microsoft authentication pages, lowering the technical bar for running credential theft campaigns at scale. Investigators estimate more than 1800 cybercriminals used the platform to launch nearly 15,000 phishing campaigns monthly since late 2024.

A documented campaign from February used tax-themed lures paired with personalized QR codes, targeting manufacturing and healthcare organizations. Victims who scanned the code were routed to a fake Microsoft sign-in page. In its more advanced mode, Kratos used a Node.js reverse proxy to act as an adversary-in-the-middle, intercepting active session cookies in real time. This let attackers bypass standard MFA controls even when a victim completed a normal-looking login.

Why it succeeded

Several factors combined to make this attack effective:

  • QR codes obscure the true destination URL, making it harder for recipients to spot a lookalike domain before scanning
  • Seasonal tax-related urgency pushed recipients to act quickly rather than verify the request
  • The authentication pages closely mimicked genuine Microsoft sign-in screens, so the login flow felt normal
  • Session cookie theft meant that even successful MFA completion did not stop the compromise

What to watch for

Defenders and employees should treat certain signals as red flags:

  • Unsolicited messages asking to scan a QR code to "review documents" or sign in
  • Sign-in prompts tied to tax season or other seasonal deadlines that create urgency
  • A Microsoft-branded login page reached through a link or QR code rather than a bookmark or known company portal
  • Unusual account activity following a sign-in event, which may indicate a stolen session rather than just stolen credentials

Once an account is compromised, attackers used it as a foothold for business email compromise, lateral data theft, and further phishing inside the organization, so a single successful login can have wide-reaching consequences.

How to build resistance

Organizations in manufacturing, healthcare, finance, payroll, and HR should reinforce a few habits across all employees:

  • Treat QR-code based sign-in requests as high risk and verify the destination through a trusted path, such as a bookmark or known internal portal, before entering credentials
  • Recognize that MFA alone does not stop session cookie theft; phishing-resistant MFA methods reduce this risk
  • Train staff to recognize convincing but fake Microsoft sign-in pages, especially those reached via email links or QR codes
  • Encourage immediate reporting of unexpected sign-in prompts so security teams can respond before a stolen session is used for BEC or further phishing

The Kratos case shows that phishing kits have matured to the point where MFA bypass is a built-in feature, not an edge case, making user awareness and verification habits an essential complement to technical controls.

Key findings

  • Law enforcement seized “over 200 servers” during “Operation Olympus Blade,” dismantling the Kratos phishing-as-a-service infrastructure and arresting the suspected developer in Indonesia.
  • Investigators estimate “more than 1800 cybercriminals utilized the platform to launch nearly 15,000 phishing campaigns monthly since late 2024.”
  • Kratos provided “toolkits designed to generate convincing Microsoft authentication pages,” enabling credential theft and unauthorized access.
  • A more advanced Kratos mode used an “adversary-in-the-middle (AitM)” Node.js reverse proxy to “intercept active session cookies in real-time,” effectively bypassing MFA.
  • Compromised accounts were then used for “business email compromise (BEC), lateral data theft, and secondary phishing attacks.”
  • A documented February campaign used “tax-themed lures and personalized QR codes” targeting “American manufacturing and healthcare organizations.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Payroll, HR, Executives, IT Helpdesk.
  • Affected industries: Manufacturing, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft login / Microsoft 365 sign-in, Microsoft authentication / Microsoft 365.

Red flags to watch for

  • Uses a QR code to hide the true destination URL
  • Urgent/seasonal tax pressure to act quickly
  • Sign-in page looks like Microsoft but is not reached through a normal company process/bookmark
  • Unexpected sign-in demand not tied to a known task
  • Link leads to a lookalike login experience
  • Login completes, but attacker can still access the account (session cookie theft)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the Kratos phishing-as-a-service platform?

Kratos was a phishing-as-a-service platform that provided toolkits for generating convincing Microsoft authentication pages, used by more than 1800 cybercriminals to launch nearly 15,000 phishing campaigns monthly since late 2024.

How did Kratos bypass multi-factor authentication?

An advanced Kratos mode deployed a Node.js reverse proxy acting as an adversary-in-the-middle, intercepting active session cookies in real time and effectively bypassing standard MFA controls.

How were QR codes used in this attack?

A February campaign used tax-themed lures and personalized QR codes to target American manufacturing and healthcare organizations, directing victims to fake Microsoft sign-in pages.

What happened after accounts were compromised?

Compromised accounts gave attackers footholds to carry out business email compromise, lateral data theft, and secondary phishing attacks.

Read the video transcript

Imagine this email: “Tax-season update: scan your personalized QR code to sign in and review documents.” Looks routine, right? Behind that QR code could be Kratos, a phishing-as-a-service kit. It spins up a perfect-looking Microsoft 365 sign-in, then uses an adversary-in-the-middle proxy to grab your password and even your session cookie, bypassing MFA while your login still looks successful. That’s how February’s Kratos campaigns hit U.S. manufacturing and healthcare: tax-themed emails, personalized QR codes, fake Microsoft auth pages, then business email compromise and invoice fraud from real mailboxes that had MFA turned on. Your move: if any email or QR code sends you to a Microsoft login, stop. Don’t sign in there, close it, and instead open our usual Microsoft 365 portal from your bookmark or company link and sign in only from that trusted path.

Similar attacks