22 Jul Security Alert: The Kratos Kit Is Down — but the MFA-Bypass Technique It Sold to 1,800 Criminals Is Not
On Monday, the Frankfurt cybercrime prosecutor and Germany’s Federal Criminal Police Office, working with US authorities, pulled more than 200 servers offline and announced the takedown of Kratos — a phishing kit German investigators called one of the most widely used criminal platforms in the world. Indonesian police arrested the man they say built and ran it. That is genuinely good news. But before any dental practice files it under “handled,” here is the part that matters for your office: Kratos did not just steal passwords. It stole live Microsoft 365 sessions, and that technique walks straight past the multi-factor authentication most practices believe is protecting them.
What Kratos Actually Did
Investigators estimate Kratos had roughly 1,800 paying customers running about 15,000 phishing campaigns a month, with victims numbering in the hundreds of thousands across more than 30 countries since late 2024. It ran like a franchise: criminals paid in cryptocurrency, signed up through a website and a Telegram shop, and pointed a working attack kit at their chosen targets. No skill required. Microsoft’s threat intelligence team has tracked the same kit under the name SneakyLog since early 2025, and documented campaigns aimed squarely at manufacturing, retail, and healthcare.
The security firm ANY.RUN, which reverse-engineered the kit, found operators could choose one of two modes. The first is an ordinary fake login page that simply harvests the username and password. The second is the dangerous one: a reverse proxy that relays your login to Microsoft in real time, lets the sign-in succeed — MFA prompt and all — and copies the resulting session cookie as it passes through. That cookie is the key. Present it, and Microsoft treats the attacker as you, already authenticated, no second factor required.

Why “We Have MFA” Is No Longer the End of the Sentence
For years the honest advice to every dental practice was: turn on multi-factor authentication and you close the overwhelming majority of email account takeovers. That advice was correct, and it is still worth doing on day one. But adversary-in-the-middle kits like Kratos are precisely the technique built to defeat it. The attacker is not guessing your password and getting stopped by a code — they are letting you complete the whole login, code included, and stealing the proof-of-login afterward.
The practical consequence is a nasty one that many practices get wrong during an incident. When you learn an account was phished and you reset the password, you feel safe. But a stolen session survives a password reset. The attacker’s copied cookie keeps working until that session is explicitly revoked or it naturally expires. A reset alone, in a reverse-proxy compromise, is a false sense of security.

What This Looks Like Aimed at a Dental Office
Kratos campaigns favoured tax-themed lures — a W-2 or invoice document carrying a QR code personalized to the recipient, leading to a fake Microsoft 365 login. Substitute the lure your staff would actually open on a busy morning: a shared radiograph, an insurance pre-authorization, a supplier invoice, a “you have a new secure message” notice. The front desk clicks, sees a pixel-perfect Microsoft sign-in, enters credentials, approves the MFA prompt on their phone because they did just try to log in… and the session is gone.
From one phished mailbox, the familiar path opens up: reading patient correspondence, resetting other internal passwords, sending invoice-redirection fraud to your suppliers from a trusted internal address, and quietly spreading to other accounts inside your Microsoft 365 tenant. For a practice, an attacker reading a mailbox full of patient names, appointment details, and insurance correspondence is not merely an IT nuisance — under Ontario’s Personal Health Information Protection Act it is a privacy breach with mandatory notification obligations, and for practices with US exposure it is a HIPAA event on its own clock.

The Takedown Is Real, but the Technique Outlived It
It is worth being clear-eyed about what this week’s law-enforcement action did and did not accomplish. The servers are offline and, the BKA says, Kratos-powered campaigns cannot currently run. What the takedown did not touch is the roughly 1,800 customers or the kit code they already possess. ANY.RUN found Kratos running on disposable domains, compromised WordPress sites, and hosting shared with other adversary-in-the-middle kits — the kind of setup that tends to reappear under a new name once the original servers go dark. Adversary-in-the-middle phishing is now a commodity. Planning your defenses around one dead brand is a mistake; plan them around the technique.
What to Actually Do This Week
These are concrete, checkable steps — hand them to whoever manages your practice’s Microsoft 365:
- Move toward phishing-resistant sign-in. Passkeys, Windows Hello for Business, or FIDO2 security keys cannot be relayed by a reverse proxy the way a one-time code can. Start with the highest-value accounts: owners, administrators, and anyone with billing access.
- Enable Conditional Access. Restricting sign-ins to known devices and expected locations sharply narrows where a stolen session can be used, even if a cookie is captured.
- Know how to revoke sessions, not just reset passwords. After any suspected phishing, revoke the account’s active sessions and refresh tokens. A password reset alone does not evict a stolen session.
- Shorten session lifetimes on sensitive roles so a captured cookie is useful for hours rather than weeks.
- Turn on mailbox auditing and alerting for new inbox rules, mass forwarding, and impossible-travel sign-ins — the classic fingerprints of a mailbox takeover in progress.
- Coach staff on the one detail that survives good lures: check the domain in the address bar before typing a password, and treat any QR code that lands you on a login screen as hostile.

Where Compudent Systems Fits In
Compudent Systems works with dental and medical practices across the GTA and Ontario, so we look at Microsoft 365 the way an attacker does: as the front door to patient correspondence, billing, and every other account it can reach from there. We can review your Conditional Access and MFA posture, move your high-value accounts onto phishing-resistant sign-in, configure session-revocation and mailbox-auditing so a takeover is caught and cut off quickly, and make sure your team knows the difference between resetting a password and actually evicting an intruder.
If you are not certain whether your practice could tell the difference between a normal login and a hijacked session — or how you would revoke one at 8 a.m. on a Monday — that is exactly the gap worth closing before someone else finds it. Contact Compudent Systems to arrange a Microsoft 365 security review.

Sources & further reading: