# Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

> **Open Intelligence Dossier** · First detected: 2026-07-22 21:07 UTC · Category: Technology

## Executive Summary
Law enforcement agencies dismantle the Kratos phishing kit designed to hijack Microsoft 365 accounts.

## Intelligence Brief
Law enforcement authorities have successfully dismantled the Kratos phishing kit, a specialized tool built specifically to steal Microsoft 365 sessions and bypass multifactor authentication protocols. These operations utilized fake procurement emails to lure victims into revealing sensitive credentials. Furthermore, the threat actors behind the activity abused compromised Outlook accounts and exploited the Microsoft Device Code Flow mechanism to facilitate the account takeovers. The coverage emphasizes the technical sophistication of the threat, highlighting how attackers managed to circumvent standard multi-factor security barriers.


This trend emerges against a backdrop of increasing sophistication in credential theft operations targeting cloud productivity suites. As organizations increasingly adopt cloud-based platforms like Microsoft 365, malicious actors continuously develop specialized phishing kits and abuse native authentication features, such as device code flows, to maintain persistence and evade detection. The reliance on compromised Outlook accounts to launch further attacks demonstrates a cyclical abuse of corporate communication channels for lateral movement and credential harvesting. Coverage does not yet specify which police agencies led the operation or whether any arrests were made in connection with the dismantling of the Kratos phishing kit.


Future reporting will likely track the identification of the individuals behind the infrastructure and whether similar kits emerge to fill the gap left by its removal. Observers and enterprise security teams must monitor ongoing advisories regarding the abuse of Microsoft Device Code Flow and compromised Outlook environments to protect against similar intrusions.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| CyberSecurityNews | Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions | [Source Link](https://news.google.com/rss/articles/CBMidkFVX3lxTE5aWDJWbmlyWUNSXzEzc0FQUjZwdFpyQjZhbVlXVjM0ZnpYVEN4d2hlbUFsRU1yako2VXRCaVJaVTZfNXZqN3dKeWU3eHhCNEt3SDhPRGg5OU5EZW5pbGw4UlpXekFMYmxERnRzSFFuc2h2c2N6ZUE?oc=5) |
| Intelligent CISO | Phishing campaign targets global institutions with fake procurement emails | [Source Link](https://news.google.com/rss/articles/CBMiugFBVV95cUxOV2JUbDRFWk9aM1BZNENrVWxhbVZZa3JnVUJZSnUtX05kUzVrc095R0M5SDVrbDNVYlNvbjFzeFlycmtYaUlPRE9UOUM1czNUMWdrMlRtYUR3TTBrZXBrVXdsVUVqUVJFUGpZZVNXQWl1VTFJSTM4aDJqNDV2LWdCYXJRcGJWaC1MLUFwUUlKRFYxV0hsNjJKSVBBdDlRdXRfb1gzMEVGRkNTcm51Z1lzcWR1Q3JQUHBHeXc?oc=5) |
| cyberpress.org | Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts | [Source Link](https://news.google.com/rss/articles/CBMiWkFVX3lxTE5NWjB3dEFRUlF2Nk5ORGIxejEyelhRWmZnQzZXMHBPeng1X2Q3OFNBMk5Ja0FrRDYwYm1xRWJWcXpFdWM3b0VyTUhQWFRXVE9vMnl0YTYwQzhSZ9IBWkFVX3lxTE5NWjB3dEFRUlF2Nk5ORGIxejEyelhRWmZnQzZXMHBPeng1X2Q3OFNBMk5Ja0FrRDYwYm1xRWJWcXpFdWM3b0VyTUhQWFRXVE9vMnl0YTYwQzhSZw?oc=5) |
| The Hacker News | Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA | [Source Link](https://news.google.com/rss/articles/CBMigAFBVV95cUxOZGRfUGh5d09WeVoxT3FyY3BGS25hbUpBWl84NjlCUEk5ck5wN1pubXVfc3JlbE9selV0S1lkemFpQ1dnSTdCbDRHbkRCRXZVX0dxNUVUMTk5ZXBwM2dpTHRJMDMwQ25MWnRPdjk0amYzUEp5UldLQUNNU2JmUUlKcg?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-07-22/police-dismantle-kratos-phishing-kit-built-to-steal-microsoft-365-sessions-and*
