PULSE the living trend engine
◼ Archived Technology 🔮 PULSE predicts: fades by tomorrow

New phishing kits target Microsoft 365 accounts, evade MFA

New phishing kits including Kratos and Forg365 are targeting Microsoft 365 accounts by evading multi-factor authentication through advanced technical maneuvers.

9sources
13articles
10velocity
+0%since first seen
45d agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A series of sophisticated phishing operations are currently targeting Microsoft 365 users. According to coverage from BleepingComputer and The National CIO Review, attackers have deployed new phishing kits specifically designed to evade multi-factor authentication (MFA). These operations include the use of the Kratos Phishing-as-a-Service (PhaaS) platform, which utilizes SharePoint links and Cloudflare Turnstile anti-bot checks to facilitate credential exfiltration. Additionally, the Forg365 PhaaS platform is targeting accounts through adversary-in-the-middle (AitM) session theft and device code abuse. Other reported methods involve the use of fake Microsoft Entra passkey enrollments to gain unauthorized access to corporate environments. Multiple security organizations and news outlets are tracking these developments.

BleepingComputer and The Hacker News highlight the emergence of these kits, while Okta has specifically warned of widespread vishing campaigns targeting Microsoft 365 customers. SecurityWeek further emphasizes the vishing threats detailed by Okta. Further technical analysis from cyberpress.org describes how Kratos employs obfuscated login pages and PHP endpoints for the exfiltration of sensitive credentials. Meanwhile, The Hacker News reported that a misconfigured server inadvertently revealed three separate Evilginx phishing operations that were actively targeting Microsoft 365 users. This trend is significant due to the high financial stakes and the persistence of the access gained. According to News4JAX, the FBI has issued a warning regarding the Kali365 phishing platform, and reports indicate that users in Florida have suffered losses totaling $12 million.

The technical nature of these attacks is particularly dangerous; gbhackers.com reports that attackers are abusing OAuth device codes and Entra ID enrollment to secure persistent access to Software-as-a-Service (SaaS) environments. CSO Online notes that tools like Forg365 are effectively lowering the barrier for entry, making account takeovers more accessible for less skilled attackers. Future developments will likely center on the mitigation of these specific phishing platforms. Coverage suggests that the focus remains on the abuse of Entra ID enrollment and the use of OAuth device codes for persistent access. Observers are monitoring the impact of the Kali365 platform following the FBI's warning and tracking the financial fallout in regions like Florida. The continued use of Cloudflare Turnstile by Kratos and the session theft capabilities of Forg365 indicate a trend toward bypassing traditional MFA, which means security professionals will need to watch for new indicators of compromise associated with AitM attacks.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 34d ago.

Quick answers

What are some of the specific phishing kits targeting Microsoft 365?

The coverage mentions Kratos, Forg365, and Kali365 as platforms being used to target users.

How are attackers bypassing multi-factor authentication (MFA)?

Attackers are using adversary-in-the-middle (AitM) session theft, abusing OAuth device codes, and employing fake Microsoft Entra passkey enrollments.

What financial impact has been reported regarding these attacks?

News4JAX reports that Floridians have reported $12 million in losses related to the Kali365 phishing platform.

Coverage (13)

Topics

Related trends