All malware guidance

Explainer

Phishing kits

Rentable phishing-as-a-service kits that proxy real sign-in pages to steal passwords and session cookies, bypassing common MFA.

In this section

What it is

A phishing kit is a ready-made package of fake login pages, hosting tools and a control panel. The most dangerous current kits are adversary-in-the-middle (AiTM) tools sold as phishing-as-a-service (PhaaS): subscribers pay for access, pick a template for Microsoft 365, Gmail or another service, and send their own lures. Microsoft describes how an AiTM kit sits between the victim and the real sign-in service, relaying traffic in both directions.

How it gets in

Delivery is ordinary phishing: emails, QR codes, shared-document notices or tax and invoice themes that lead to a convincing sign-in page. Because the page proxies the genuine service, the victim sees real branding and completes a real MFA challenge.

What it steals

Besides the username and password, the kit captures the session cookie issued after the victim finishes MFA. Microsoft said Tycoon2FA could bypass most common MFA methods, including SMS codes, one-time passcodes and push notifications, and that stolen sessions could survive a password reset unless active sessions were revoked. Phishing-resistant methods such as FIDO2 keys and passkeys defeat this because they are bound to the genuine website.

Notable kits in 2025-2026

  • Tycoon2FA: run by a group Microsoft tracks as Storm-1747. Microsoft said that by mid-2025 it accounted for about 62% of phishing attempts Microsoft blocked, reaching more than 500,000 organisations a month. A coalition including Microsoft and Europol seized 330 domains in March 2026.
  • Kratos: known to Microsoft as SneakyLog. Germany's BKA said in July 2026 that more than 200 servers were taken down and the alleged developer was arrested in Indonesia; it estimated 1,800 criminal customers running about 15,000 campaigns a month. Our coverage.

How it is used downstream

With a live session, attackers read mail, set up inbox rules to hide their activity, register their own authenticator app for persistence, and send further phishing from the trusted account, Microsoft said. Compromised mailboxes feed business email compromise and invoice fraud, and cloud access can be sold on or used to reach file shares and internal apps. Kit operators themselves profit from subscriptions: the BKA estimated the Kratos group earned more than EUR 300,000 since 2024.

Detect and contain

Detection signals

  • Sign-ins where the session is reused from a different IP, ASN or device shortly after authentication
  • New inbox rules, mail forwarding or MFA methods added soon after a sign-in
  • Users reaching recently registered domains that imitate Microsoft 365 or Google login pages

Reduce the blast radius

  • Phishing-resistant MFA (FIDO2 keys, passkeys, Windows Hello for Business), starting with admins and finance
  • Conditional access requiring compliant devices, plus token protection where available
  • Revoke sessions, not just passwords, when an account is compromised

Questions people ask

What is a phishing kit?

A phishing kit is a packaged set of fake login pages and tools that lets criminals launch phishing campaigns without building anything themselves. Many are now rented as phishing-as-a-service, with templates for Microsoft 365, Google and banks, hosting, and a dashboard that collects stolen credentials and session cookies from victims in real time.

What is an adversary-in-the-middle (AiTM) phishing attack?

In an AiTM attack, the phishing site acts as a relay between the victim and the real login page. The victim enters a password and approves MFA as normal, but the attacker's server captures the session cookie the real service issues. The attacker then reuses that cookie to enter the account without needing MFA again.

Can phishing bypass MFA?

Yes. AiTM phishing kits such as Tycoon2FA and Kratos steal the session created after a successful MFA sign-in, which works against SMS codes, authenticator codes and push approvals. Phishing-resistant MFA such as passkeys and FIDO2 security keys resists this because the credential only works on the genuine website's domain.

What should I do if I entered my password on a phishing page?

Change the password from a trusted device, then sign out of all sessions or ask IT to revoke them, because stolen session cookies can keep working. Check for new inbox rules, forwarding addresses and unfamiliar MFA methods on the account, and report the page to your IT or security team.

Further reading