Back to all lessons
Awareness Lessons
3 months ago

Kratos PhaaS Platform Dismantled: 15,000 Monthly Phishing Campaigns Targeting Microsoft Credentials

The Kratos phishing-as-a-service platform enabled approximately 1,800 criminal customers to run roughly 15,000 phishing campaigns per month by offering ready-made fake Microsoft authentication pages, dramatically lowering the technical barrier for credential theft. The platform's success underscores how commodity cybercrime services amplify risk at scale, turning sophisticated attacks into a purchasable subscription. At its core, the threat exploited users' inability to distinguish legitimate Microsoft login pages from convincing fakes, making credential harvesting trivially easy. This matters because stolen credentials are a primary initial access vector for ransomware, data breaches, and business email compromise, creating downstream harm far beyond the phishing act itself.

Tactical Insight

Immediate actions

  • Deploy phishing-resistant multi-factor authentication (e.g., FIDO2/passkeys) across all Microsoft 365 and identity provider accounts to neutralize stolen password value.
  • Enable Microsoft Defender for Office 365 anti-phishing policies and Safe Links to automatically detect and block lookalike authentication pages.

User awareness measures

  • Conduct regular simulated phishing exercises specifically mimicking Microsoft login page lures to train employees to recognize credential-harvesting attempts.
  • Train staff to verify URLs in the browser address bar before entering credentials and to report suspicious login prompts immediately to the security team.

Long-term improvements

  • Implement Conditional Access policies that enforce device compliance and location-based controls, reducing the impact of any credentials that are successfully stolen.
  • Adopt a Zero Trust identity model with continuous authentication monitoring to detect and block anomalous login attempts in real time.
  • Integrate threat intelligence feeds covering known PhaaS infrastructure to proactively block emerging phishing domains at the DNS and email gateway layers.