Skip to content

Observed infrastructure

Last seven days

First activity
Sep 4, 2026
Last activity
Sep 4, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

MITRE ATT&CK

Kratos in ATT&CK

21 distinct techniques

Reporting

Research mentioning Kratos

Aug 25
Cyber Security News

EvilTokens Doesn’t Just Steal Microsoft Sessions-Its AI Tells Attackers Who to Scam Next

Researchers reported that the EvilTokens phishing-as-a-service platform is being used to steal Microsoft 365 access tokens through OAuth device code phishing, with one campaign abusing free Notion accounts and malicious PDFs to lure victims. In the activity tracked as Doubloon Dredger, attackers sent legitimate-looking Notion document-sharing notifications from compromised accounts impersonating senior executives, then redirected targets to phishing pages disguised as Adobe Acrobat authentication prompts. Victims were instructed to enter a verification code on Microsoft’s legitimate sign-in or device code page, allowing Microsoft to issue authorization tokens directly to the attackers without requiring password theft. The operation has targeted organizations in manufacturing, telecommunications, retail, healthcare, and logistics, and researchers said EvilTokens has been active since at least February 2026 and is marketed largely through Telegram. Flare said the platform goes beyond session theft by analyzing compromised mailboxes, using AI to summarize content and identify likely fraud opportunities, and helping operators craft tailored business email compromise messages based on real payment workflows and relationships. Reported activity included a 16-day wave affecting 344 organizations across five countries, while separate research found more than 1,000 infrastructure-related search results and 66 email attachments leading to EvilTokens pages; defenders were urged to restrict or disable device-code authentication where possible and monitor for anomalous token grants, inbox rule creation, mailbox searches, token reuse, and suspicious outbound email.

Aug 24
Flareio

What is EvilTokens? Inside the PhaaS Platform

Aug 24
Infosecurity Magazine News

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens - Infosecurity Magazine

Jul 22
Cyber Security News

Authorities Shut Down Phishing Empire Launching 15,000 Attacks Every Month

German authorities, working with the United States and Indonesia, dismantled the core infrastructure of Kratos, a phishing-as-a-service platform described as one of the world’s most widely used criminal phishing services. Investigators seized or neutralized more than 200 servers and arrested the alleged developer and technical administrator in Indonesia, a move authorities said rendered the service inoperable. The action was carried out under Operation Olympus Blade, and the FBI took control of Kratos-linked domains to support follow-on investigation and customer identification. Kratos supplied Microsoft-themed phishing pages designed to steal credentials and session cookies, allowing attackers to hijack accounts and bypass multi-factor authentication. Authorities said the platform was used by roughly 1,800 criminal customers to launch about 15,000 phishing campaigns per month against victims in at least 35 countries, with organizations in the United States and Europe—particularly in manufacturing, retail, healthcare, and education—among the main targets. Investigators estimate the operation generated more than €300,000 since 2024.

Jul 22
The Hacker News

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

Jul 22
Help Net Security

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns - Help Net Security

Jul 22
Teiss News

teiss - News - German and U.S. authorities dismantle Kratos phishing kit, arrest developer in Indonesia

Jul 22
Trend Micro Research

Law Enforcement Takes Down Kratos/Sneaky2FA Phishing Service, With an Assist From TrendAI™ | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.