Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Kratos

41
Global rank
46 infographic chevron month
Month rank
27 infographic chevron week
Week rank
0
IOCs

Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.

Phishingkit
Type
Unknown
Origin
1 September, 2025
First seen
7 September, 2026
Last seen

How to analyze Kratos with ANY.RUN

Type
Unknown
Origin
1 September, 2025
First seen
7 September, 2026
Last seen

IOCs

IP addresses
20.250.198.32
23.50.131.100
48.209.133.15
52.222.136.123
40.126.32.72
150.171.28.11
92.123.104.41
150.171.109.99
23.56.203.142
151.101.65.155
13.107.9.156
142.250.154.95
104.18.10.207
13.107.246.45
192.185.170.196
150.171.109.106
216.150.1.65
150.171.109.105
52.159.82.83
23.50.131.104
Hashes
f1b8922f83095058699b69831562a2aaed78b0fc0fa7fb32436ba12ace3a3e77
9d1a1a5e3b5e5de8a6c76ded7a01fa01709d426232b0048c9ee6ba0c5c1b8b42
ee810a451aea499c3d6f89edb840ed025df0937874485a211a3bb39f915f4ea0
9efe2042cb81f0686dcf4b7e3822fd641d1e1079943231f6aad54b7879a5c81c
2003175e478394fea88e934a92663d221ff7bc417c5039ee9bcd4c15fa7c4ef7
50e3aeaedc540636c86fb006ee1c8d84c8f0fd6fd28b71eafae2e1bcc9700c95
619100272d3a9e55037b39081ae8032a37b1c11aa36691288e2f6cc17c7ca153
112fec798b78aa02e102a724b5cb1990c0f909bc1d8b7b1fa256eab41bbc0960
d0b1a869600d21076a3fa8b5f52546e55920588ce73dfb7e56ca9dc08bdcaf3e
aa03dc59bdca72631d2301e4297cfa030bd31b907dc138e7b973d12311c90a22
05b85d96f41fff14d8f608dad03ab71e2c1017c2da0914d7c59291bad7a54f8e
0973c1d64c88adc8e3c950410cb58b288f72118d5965b78049438deb8f2f9683
a3eea60418786a98870edcbbf7993985c8682bc07c1cb7521b2f144f27e2176b
66af34efad8ad6be518c955fb42163a9f1178a2f51b6b16e7864a46973b04349
44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a
3a790b6c0d26d7a4d292cb27f992eafaff42c37e9318b2ab704207039127fcb8
4825e7c6302ca565622557bd9fc6965e90979bd54cf302749a4d6b8d644f8389
ccbb779363f7f2b5174e25ebb1bba5dd9b72c4e08c9f8d64751e95ed3db85571
04bec01401dc633a4e305486256cb72fb9eaa3accb6e80f26a093aea17ee4c48
b97b21c86f4c6f3584da4a693a88c0b11c85f6c644f1ac435c7d0d091b87c420
Domains
arc.msn.com
edge-consumer-static.azureedge.net
stackpath.bootstrapcdn.com
www.microsoft.com
uhf.microsoft.com
www.office.com
edge.microsoft.com
xpaywalletcdn.azureedge.net
settings-win.data.microsoft.com
www.clarity.ms
config.edge.skype.com
www.bing.com
outlook.office.com
cdn.usefathom.com
google.com
assets.msn.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
js.monitor.azure.com
nleditor.osi.office.net
ocws.officeapps.live.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=188&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%206%20model%2014%20stepping%203&oemmodel=dell&updateoffereddays=344&processormanufacturer=authenticamd&installdate=1662378835&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&isflightingenabled=0&osskuid=48&processorclockspeed=3593&totalphysicalram=4096&securebootcapable=0&app=waasassessment&processorcores=4&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=188&processormodel=intel%28r%29%20core%28tm%29%20i5-6400%20cpu%20%40%202.70ghz&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://caballeroes.pagy.site/
https://caballeroes.pagy.site/_next/image?url=https%3a%2f%2fmedia.pagy.co%2fa03a54e5.webp&w=256&q=75
https://caballeroes.pagy.site/_next/static/chunks/webpack-d22d095bb86a7c03.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/c26d6d2d-37e2d36c5bab8d82.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/9984-c49220e877ed0ee0.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/main-app-43064fceb641e856.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/app/site/%5bhost%5d/layout-3e42cb9ee32e903f.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/9856-9293f61673a43da6.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/6975-7ddcf62ca09c69ab.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/4944-23907d7edbfbe4d2.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/8454-6407aef2cb9344ec.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/8247-10c35df421740255.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://caballeroes.pagy.site/_next/static/chunks/app/site/%5bhost%5d/%5b%5b...path%5d%5d/page-5b366e30b48c2013.js?dpl=dpl_5u8ik4rdywk3dvapz3kfcfqx2zug
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3593&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=188&processorcores=4&branchreadinesslevelraw=16&totalphysicalram=4096&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260246&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&activehoursstart=8&securebootcapable=0&activehoursend=17&devicefamily=windows.desktop
https://caballeroes.pagy.site/favicon.png
https://caballeroes.pagy.site/_next/image?url=https%3a%2f%2fmedia.pagy.co%2fa03a54e5.webp&w=3600&q=75
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 4972
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 4410
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 10625
comments 0

The Kratos PhaaS: How Turnkey Phishing Scales Microsoft 365 Account Takeovers

Key Takeaways

  • Kratos is a sophisticated Phishing-as-a-Service (PhaaS) platform specifically engineered to industrialize the theft of Microsoft 365 credentials and bypass multi-factor authentication (MFA).
  • The platform shares hosting infrastructure with other AiTM phishing kits, including Tycoon, Flowerstorm, Sneaky2FA, and EvilProxy.
  • In July 2026, a major international law enforcement action known as Operation Olympus Blade disrupted the service, leading to the shutdown of over 200 servers and the arrest of the lead developer in Indonesia.
  • Despite its disruption, the kit was highly scalable, supporting over 1,800 criminal subscribers who launched an estimated 15,000 phishing campaigns per month.
  • Kratos utilizes a decoupled architecture, ensuring that harvested data is exfiltrated in real-time to Telegram bots, which allows stolen information to remain accessible even if the phishing URLs are taken down.
  • ANY.RUN researchers identified unique technical fingerprints, specifically the presence of barr.svg and lg.svg assets, which provide near-100% accuracy in attributing malicious activity to the Kratos family.

Kratos phishing attack exposed in ANY.RUN's Interactive Sandbox Kratos phishing attack exposed in ANY.RUN's Interactive Sandbox

What is Kratos?

Kratos is a subscription-based cybercrime service that provides a "turnkey" solution for threat actors looking to compromise Microsoft 365 environments at scale. As a Phishing-as-a-Service (PhaaS) model, it lowers the barrier to entry for low-skilled attackers by offering a centralized administrative dashboard that automates the deployment of phishing domains, VPS infrastructure, and anti-bot protections.

Evolution of Kratos phishing Evolution of Kratos phishing

The kit represents a significant technical evolution from its predecessor, Sneaky2FA. While earlier versions functioned as traditional info-stealers, the modern Kratos platform utilizes adversary-in-the-middle (AiTM) techniques to relay live authentication sessions between victims and legitimate Microsoft login servers. This allows the kit to capture not only passwords but also the session tokens required to bypass MFA challenges.

The "business" of Kratos is highly organized, operating through Telegram-based subscriptions where affiliates pay for access to ready-made phishing templates, such as those mimicking Adobe Creative Cloud or DocuSign. The platform's internal logic includes advanced features such as:

  • Automated Vetting: Using services like geoplugin[.]net to geolocate victims and filter out non-target regions or security researchers.
  • Anti-Analysis Defenses: Integrated support for Cloudflare Turnstile, reCAPTCHA, and hCaptcha to prevent automated scanners from detecting the phishing pages.
  • Multi-Generational Development: ANY.RUN has tracked the kit through three distinct generations (V0, V1, and V2), showing a steady progression toward more convincing brand impersonation and more heavily obfuscated code to evade security vendor signatures.

By utilizing an encrypted exfiltration chain via the Telegram Bot API, Kratos ensures that its criminal operators can receive stolen credentials instantly and securely, blending their malicious traffic with legitimate web service activity.

How Kratos Threatens Businesses and Organizations

Kratos represents a significant escalation in the threat landscape because it moves beyond simple password harvesting toward total account takeover (ATO) and long-term persistence within corporate environments.

By industrializing the theft of Microsoft 365 credentials, the platform creates several critical risks for modern enterprises:

  • Advanced Business Email Compromise (BEC): Once an account is compromised, attackers can monitor executive communications, intercept ongoing financial conversations, and alter payment instructions. Because these fraudulent requests originate from a legitimate, trusted mailbox, they are extremely difficult for both automated filters and employees to detect.
  • Bypassing Multi-Factor Authentication (MFA): Unlike traditional phishing kits that only steal passwords, Kratos employs Adversary-in-the-Middle (AiTM) techniques. By relaying live authentication sessions between the victim and Microsoft's real servers, the kit captures active session tokens. This allows attackers to bypass MFA challenges entirely, as the token confirms to Microsoft that the "user" has already authenticated.
  • Persistent Infrastructure Access: A major danger of Kratos is its ability to maintain access even after a security incident is identified. If an attacker gains session access through a stolen token, a simple password reset may not be enough to remove them. Unless security teams explicitly revoke active sessions and refresh tokens, the threat actor can remain inside the environment indefinitely.
  • Data and Partner Exposure: Compromised accounts provide a gateway to sensitive business data stored in SharePoint, Teams, and OneDrive. This exposure often extends to third-party partners and suppliers, as attackers can use the compromised account to harvest contact lists and launch secondary attacks against the organization’s entire supply chain.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The Kratos platform is a global threat that has successfully targeted victims in over 30 countries. While its reach is international, analysis of ANY.RUN Interactive Sandbox data and industry reports reveals specific geographic and sectoral concentrations:

  • Primary Focus on the United States: The U.S. remains the most targeted region, accounting for approximately 33% of all observed Kratos activity.
  • Strong Concentration in Southern Europe: Researchers have identified a heavy focus on Spain and other Southern European nations. This is evidenced by the use of Spanish-language "tokens" in the phishing URLs, such as abogados (lawyers), factura (invoice), and dgt (Spain’s traffic authority).
  • Sector-Agnostic Targeting: While the platform hits a wide range of industries, the targeting is largely opportunistic. Vulnerable sectors include legal and financial services, education and healthcare, industrial and SMBs.

Ultimately, any organization that relies on Microsoft 365 for its daily operations is within the scope of Kratos. The kit does not exploit a software vulnerability but rather exploits the human element and the ubiquitous nature of Microsoft’s authentication workflows.

How Does Kratos Malware Function? (The Sandbox Analysis)

Detonating a Kratos sample in the ANY.RUN Interactive Sandbox provides a clear, step-by-step view of how the PhaaS platform operates. By moving beyond static analysis, defenders can observe the following stages of the attack in real-time:

Stage 1: The Intermediary Lure and "Buffer" Pages

The Kratos infection chain begins with a targeted phishing email that is frequently successful in bypassing corporate email filters and secure email gateways.

Kratos phishing email shown in ANY.RUN's Interactive Sandbox Kratos phishing email

To further evade detection by automated scanners, the attack does not link directly to the final phishing landing page. Instead, the email directs the victim to an intermediary "buffer" site hosted on a legitimate, trusted platform. In the ANY.RUN Sandbox, analysts frequently observe redirects through services such as Microsoft SharePoint, OneDrive, Canva, Tilda, or Microsoft Forms.

Stage 2: Passing the "Challengepoint"

Before the phishing form is even loaded, Kratos initiates a verification gate to filter out automated security crawlers. The victim is presented with a Cloudflare Turnstile or CAPTCHA. In the network logs, this is often identified as "challengepoint". This step ensures that the sandbox is being operated by a human, making it harder for headless security scanners to reach the payload.

Stage 3: Visual Social Engineering Hallmarks

Loading page used in Kratos attacks Loading page used in Kratos attacks

Once verified, the kit presents its unique visual identity. A distinctive feature of Kratos is the animated envelope screen. The victim sees an animation with the message “Loading in progress…” overlaid on a blurred image of an invoice or document. The browser tab title typically changes to “Authentication” during this phase. This high-fidelity branding is designed to build trust immediately before requesting credentials.

Stage 4: Real-Time Data Harvesting and Exfiltration

Kratos phishing attack exposed in ANY.RUN's Interactive Sandbox Kratos phishing attack exposed in ANY.RUN's Interactive Sandbox

The most critical part of the analysis occurs during the login attempt. Using ANY.RUN’s In-browser data inspection, analysts can deobfuscate the script behavior:

  • The Functionality: Analysts can see the submitData() function capturing the user's input (marked as di and pr parameters).
  • The Endpoints: Depending on the generation, the data is sent via a POST request to specific PHP endpoints: /next.php (V1), /save.php (V2), or /mini.php (V0).
  • AiTM Indicators: The sandbox may also record WebSocket activity, which is a strong behavioral signal of Adversary-in-the-Middle (AiTM) behavior, where the kit relays session data in real-time to bypass MFA.
Stage 5: Telegram Bot Communication

Kratos uses a decoupled architecture, meaning the exfiltration happens server-side, but its traces are visible in the sandbox's network traffic:

  • The Dropzone: The kit communicates with the Telegram Bot API to send stolen data to the attacker’s private channel.

  • Data Packaging: Credentials, IP addresses, geolocations, and device types are bundled into JSON logs, ensuring the attacker receives the data even if the phishing site is taken down immediately.

Stage 6: The Exit and Redirection

To avoid suspicion, the kit limits login attempts. In the sandbox, analysts can observe that after three failed attempts, the victim is automatically redirected to a legitimate URL. This final step is intended to make the victim believe they simply had a minor login error, delaying any potential report to their IT security team.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Kratos

ANY.RUN’s Threat Intelligence serves as a powerful proactive defense solution, allowing SOC teams to move beyond a single indicator and view the entire Kratos ecosystem through a continuously updated threat database that is based on sandbox submissions by 15K organizations and 600K security analysts.

ANY.RUN's Lookup offers latest intel on Kratos and other phishing ANY.RUN's Lookup offers latest intel on Kratos and other phishing

Threat Intelligence Lookup allows for precise family-level identification. By using the query threatName:"kratos", analysts can instantly access a consolidated view of all data related to Kratos attacks globally. This helps teams understand the current scale of the threat and determine if their specific industry or region is currently being targeted by active clusters.

One of the most effective ways to use TI Lookup against Kratos is by searching for static asset hashes. Even when attackers change their domain names or rename files, the underlying content of the kit remains largely the same.

Cross-Campaign Linking: Analysts can query for the specific SHA256 hash of the styles.css file, which has been found to connect over 630 sandbox analyses across both the V1 and V2 generations of the kit.

Asset Fingerprinting: Searching for the unique hashes of files like lg.svg (V1) or dsa.svg (V2) allows teams to identify Kratos landing pages with near-100% accuracy, even on compromised legitimate websites where the file path might be hidden.

Check this TI Lookup query based on the lg.svg and styles.css hashes:

SHA256:”c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb” AND SHA256:”cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea”

By integrating TI Lookup queries into their regular hunting workflows, SOC and MSSP teams can significantly reduce business exposure to Kratos and contain account compromise attempts before they escalate into full-scale data breaches.

ANY.RUN's TI Feeds offer a real-time stream of phishing IOCs ANY.RUN's TI Feeds offer a real-time stream of phishing IOCs

For organizations looking to automate their defense, ANY.RUN’s Threat Intelligence Feeds provide a continuous stream of the most recent network indicators (IPs, domains, and URLs) associated with active phishing campaigns. The TI Feeds are updated in real time based on the latest threat submissions to ANY.RUN’s Sandbox from 15K organizations and 600K analysts.

By integrating these feeds into SIEMs and security controls, teams can automatically block emerging phishing infrastructure and detect malicious activity before attackers establish persistence or hijack session tokens.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

While Operation Olympus Blade successfully dismantled the central Kratos infrastructure in July 2026, the broader Phishing-as-a-Service (PhaaS) ecosystem is only gaining momentum. Industry projections estimate that over 90% of all credential compromise attacks will be enabled by modular PhaaS kits by the end of 2026.

The rapid emergence of alternative platforms, such as Kali365, demonstrates that as one service is taken offline, others quickly fill the void to target Microsoft 365 environments. For organizations, the focus must shift from reacting to individual takedowns to maintaining proactive visibility through threat intelligence and adopting defense-in-depth strategies, such as revoking active session tokens rather than relying solely on password resets.

Frequently Asked Questions: Kratos PhaaS

1. What is Kratos PhaaS?

Kratos is a turnkey Phishing-as-a-Service platform used to steal Microsoft 365 credentials. It is a direct evolution of the Sneaky2FA kit.

2. How does it bypass MFA?

It employs Adversary-in-the-Middle (AiTM) techniques to proxy live login sessions and capture session tokens, allowing attackers to bypass multi-factor authentication entirely.

3. What are the key indicators of a Kratos attack?

Visually, victims see a “Loading in progress…” animation over a blurred document. Technically, the kit is identified by assets like barr.svg and lg.svg (V1) or dsa.svg and sid.gif (V2).

4. How is stolen data exfiltrated?

Stolen credentials and metadata are packaged as JSON and sent in real-time to Telegram bots, ensuring data remains accessible even if the phishing site is taken down.

5. Was the Kratos infrastructure shut down?

Yes. In July 2026, Operation Olympus Blade dismantled the service, shutting down over 200 servers and resulting in the lead developer's arrest in Indonesia.

6. Who are the primary targets?

The platform has a global reach (30+ countries), focusing heavily on the United States (33%) and Southern Europe, particularly Spain.

HAVE A LOOK AT

BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More