
Forg365 Phishing Kit Steals Microsoft 365 Sessions
Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…
German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help criminals bypass multi-factor authentication (MFA). Reporting also links the kit to tax-season lures (fake W-2 forms) and other common cloud-service themes like SharePoint and OneDrive.
Kratos was a phishing-as-a-service kit that gave criminals with little technical skill access to convincing, Microsoft-themed fake login pages. Victims who clicked a link and entered credentials had both their password and session cookie captured. Because the session cookie was stolen, attackers could potentially reuse an active login session, effectively sidestepping the extra protection multi-factor authentication is supposed to provide.
Law enforcement action, led by German authorities, disrupted the infrastructure behind the kit, reportedly taking down more than 200 servers, and authorities allege the developer or technical administrator was arrested in Indonesia. Open-source reporting also links Kratos to other kit names and connects it to a wide set of lure themes beyond Microsoft, including SharePoint, OneDrive, Microsoft Forms, Adobe, and Canva.
The kit's success came from believability and reach. It packaged convincing Microsoft sign-in pages that could be deployed at scale, and it reused everyday business workflows, like opening a shared document or reviewing a tax form, as the entry point. Because these are routine actions employees perform constantly, the phishing pages blended into normal work patterns rather than standing out as unusual requests.
Seasonal timing added pressure. Fake W-2 tax form lures targeted US citizens during tax season, when people expect to receive and act on tax documents quickly, making them less likely to scrutinize a sign-in prompt closely.
Organizations across manufacturing, retail, healthcare, and other affected sectors should reinforce a few habits. Employees should treat unexpected Microsoft sign-in prompts as suspicious and verify both the sender and the link before entering credentials. Because MFA is not a guarantee against session-cookie theft, unusual sign-in pages or prompts should be reported immediately rather than dismissed.
HR, payroll, and finance teams handling tax-season documents and other administrative requests should be especially cautious of links that ask for a login to view a form. Since attackers reuse trusted business tools like SharePoint and OneDrive as lures, document-sharing requests are best verified through a separate, known communication channel before clicking through and signing in.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Kratos was a phishing-as-a-service kit that let low-skill criminals run convincing Microsoft-themed phishing pages to steal passwords and session cookies from victims.
By stealing session cookies alongside passwords, attackers could hijack an already-authenticated session rather than needing to defeat MFA directly.
Reporting ties Kratos to fake W-2 tax forms and lure themes based on SharePoint, OneDrive, Microsoft Forms, Adobe, and Canva sign-in pages.
Victims were targeted across more than 30 countries with a heavy focus on the US and Europe, and manufacturing, retail, and healthcare were highlighted as US targets.
You get an email: “New W-2 form available” or “SharePoint file shared with you.” Looks normal, Microsoft logo and all. Behind the scenes, a kit called Kratos, also known as SneakyLog, was helping low-skill scammers spin up fake Microsoft login pages on more than 200 servers, built to steal your password and even your session cookie to bypass MFA. Here’s the trick: you click the W-2 or OneDrive link, a very Microsoft-looking sign-in pops up, but the URL is something like 'login-secure-docs[.]com' instead of microsoft.com or your usual company SSO page. If a Microsoft sign-in page appears from an email link and the URL isn’t microsoft.com or your normal SSO, stop and report it to IT, do not enter your password.

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…