New phishing kits target Microsoft 365 accounts, evade MFA
New phishing kits including Kratos and Forg365 are targeting Microsoft 365 accounts by evading multi-factor authentication through advanced technical maneuvers.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A series of sophisticated phishing operations are currently targeting Microsoft 365 users. According to coverage from BleepingComputer and The National CIO Review, attackers have deployed new phishing kits specifically designed to evade multi-factor authentication (MFA). These operations include the use of the Kratos Phishing-as-a-Service (PhaaS) platform, which utilizes SharePoint links and Cloudflare Turnstile anti-bot checks to facilitate credential exfiltration. Additionally, the Forg365 PhaaS platform is targeting accounts through adversary-in-the-middle (AitM) session theft and device code abuse. Other reported methods involve the use of fake Microsoft Entra passkey enrollments to gain unauthorized access to corporate environments. Multiple security organizations and news outlets are tracking these developments.
BleepingComputer and The Hacker News highlight the emergence of these kits, while Okta has specifically warned of widespread vishing campaigns targeting Microsoft 365 customers. SecurityWeek further emphasizes the vishing threats detailed by Okta. Further technical analysis from cyberpress.org describes how Kratos employs obfuscated login pages and PHP endpoints for the exfiltration of sensitive credentials. Meanwhile, The Hacker News reported that a misconfigured server inadvertently revealed three separate Evilginx phishing operations that were actively targeting Microsoft 365 users. This trend is significant due to the high financial stakes and the persistence of the access gained. According to News4JAX, the FBI has issued a warning regarding the Kali365 phishing platform, and reports indicate that users in Florida have suffered losses totaling $12 million.
The technical nature of these attacks is particularly dangerous; gbhackers.com reports that attackers are abusing OAuth device codes and Entra ID enrollment to secure persistent access to Software-as-a-Service (SaaS) environments. CSO Online notes that tools like Forg365 are effectively lowering the barrier for entry, making account takeovers more accessible for less skilled attackers. Future developments will likely center on the mitigation of these specific phishing platforms. Coverage suggests that the focus remains on the abuse of Entra ID enrollment and the use of OAuth device codes for persistent access. Observers are monitoring the impact of the Kali365 platform following the FBI's warning and tracking the financial fallout in regions like Florida. The continued use of Cloudflare Turnstile by Kratos and the session theft capabilities of Forg365 indicate a trend toward bypassing traditional MFA, which means security professionals will need to watch for new indicators of compromise associated with AitM attacks.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 34d ago.
Quick answers
What are some of the specific phishing kits targeting Microsoft 365?
The coverage mentions Kratos, Forg365, and Kali365 as platforms being used to target users.
How are attackers bypassing multi-factor authentication (MFA)?
Attackers are using adversary-in-the-middle (AitM) session theft, abusing OAuth device codes, and employing fake Microsoft Entra passkey enrollments.
What financial impact has been reported regarding these attacks?
News4JAX reports that Floridians have reported $12 million in losses related to the Kali365 phishing platform.
Coverage (13)
- Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials cyberpress.org · 46d ago
- Hackers targeting Microsoft 365 in widespread vishing campaign, Okta warns Cyber Daily · 46d ago
- Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks gbhackers.com · 46d ago
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 The Hacker News · 46d ago
- Attackers Find a New Way Into Microsoft 365 The National CIO Review · 46d ago
- New phishing kits target Microsoft 365 accounts, evade MFA BleepingComputer · 46d ago
- Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access The Hacker News · 46d ago
- FBI warns Kali365 phishing platform is targeting Microsoft 365 users; Floridians report $12 million in losses News4JAX · 46d ago
- Phishing for dummies: Forg365 lowers barrier to M365 account takeovers csoonline.com · 46d ago
- Hackers Abuse OAuth Device Codes and Entra ID Enrollment for Persistent SaaS Access gbhackers.com · 46d ago
- Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers SecurityWeek · 46d ago
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft The Hacker News · 46d ago
- New phishing kits target Microsoft 365 accounts, evade MFA BleepingComputer · 46d ago
Topics
Related trends
Okta skyrockets 20%, CrowdStrike surges 15% as rising AI threat boosts earnings
4 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Health systems warn patients of MyChart phishing scam
6 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Someone targeted security researchers using a fake crypto conference as a lure
Security experts and conference attendees face a targeted phishing campaign involving a fake crypto event and booby-trapped documents.
Dave Bautista Officially Set as Kratos in ‘God of War’ TV Series
5 news sources are covering this Entertainment story right now — PULSE is tracking how fast it spreads.
Microsoft confirms outage affecting search in Microsoft 365 apps
Microsoft confirms a global search outage impacting multiple 365 services including Outlook, OneDrive, and SharePoint.
New Pass-ta-key attack reveals all the things we didn’t know about passkeys
3 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.