Last seven days
- First activity
- Jul 26, 2026
- Last activity
- Jul 26, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 4 hostnames
MITRE ATT&CK
Reporting
The campaigns described in this blog appear to be the work of a single actor who leverages multiple AiTM phishing kits, including Evilginx, FlowerStorm, and Kali365, to harvest user credentials.
Kratos also shares hosting infrastructure with other AiTM phishing kits, including Tycoon, Flowerstorm, Sneaky2FA, and EvilProxy.
FlowerStorm is a widely known Phishing-As-A-Service (PhaaS) attack kit that has been active since at least mid-2024, increasingly in large scale campaigns.
Victims not only entered their credentials on the Dropbox portal but proceeded to accept an MFA prompt generated shortly after by the attacker. This replay tactic is common among synchronous-replay adversary-in-the-middle phishing kits such as FlowerStorm.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.