Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe
Kratos Phishing-as-a-Service Platform Targeting Microsoft (TL-2026-1408), also tracked as Kratos PhaaS, is a high-severity phishing campaign, first published 2026-07-16. It has no confirmed attribution, affects Microsoft Microsoft 365 (Entra ID / Office 365 authentication), maps to 19 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 38 indicators of compromise.
Key facts for TL-2026-1408
- Threat ID
- TL-2026-1408
- Also known as
- Kratos PhaaS, Kratos Kit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-16
- Last reviewed
- 2026-07-16
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- small business, legal, education, manufacturing, industrial, technology, msp mssp, government administration, public sector
- Target regions
- united states of america, spain, 039 - Southern Europe, Europe, Global (20+ countries)
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in Kratos Phishing-as-a-Service Platform Targeting Microsoft
Malware and tooling: Kratos, Cloudflare Turnstile (abused), Telegram Bot API
Kratos is an actively evolving phishing-as-a-service (PhaaS) kit that impersonates Microsoft 365 (and formerly Adobe Creative Cloud/Document Cloud) login flows, using Cloudflare Turnstile/reCAPTCHA/hCaptcha anti-bot gates, SharePoint/OneDrive/Canva/Tilda/systeme.io lure hosting, and Telegram-bot credential exfiltration to compromise organizations in 20+ countries.
How Kratos Phishing-as-a-Service Platform Targeting Microsoft works
Kratos is a subscription-based Phishing-as-a-Service (PhaaS) platform first observed operating an admin panel since at least September 10, 2025, with its phishing kit visible in ANY.RUN's Interactive Sandbox from January 2026 onward and continued activity through the July 2026 reporting window. The kit has evolved across at least three tracked generations: V0 ('PTT/SOft', a 'Secure File Access' lure with blurred invoice background, exfiltrating to mini.php under a /PTT/SOft/ path, seen on the dwbud.vilaribit.com domain and associated with only 9 sandbox sessions); V1 (the dominant generation with 1,397 identified sandbox sessions, using a shared asset fingerprint of barr.svg + lg.svg + ani.gif + res.css + styles.css, a fake Microsoft sign-in page with an animated envelope and 'Loading in progress...' splash screen, and exfiltration to next.php/nex.php/n3xt.php/officers*eur.php); and V2 (the current generation, 231 sessions, using dsa.svg + sid.gif + imag.jpg + main.js assets, jQuery 4.0 beta with obfuscated JavaScript, and exfiltration via fetch() calls to save.php). Across V1 and V2 combined, ANY.RUN identified 1,628 sandbox sessions, of which only 156 had previously been manually attributed to Kratos and 1,484 were previously unattributed to any known family — with a distinct SHA-256 shared styles.css asset connecting 636 of those tasks. A separate, harder-to-detect campaign variant observed roughly 100+ analysis sessions in a single week, replacing the static /SOft URI and 'Secure Document Access' branding with common-looking URIs and a more realistic Microsoft-style authentication interface targeting manufacturing, technology, and MSSP organizations.
The attack chain begins with phishing emails using document-share, invoice-review, and DocuSign-pending-action lures, frequently staged through legitimate cloud services (SharePoint/OneDrive account for 351 observed delivery tasks, alongside Microsoft Forms, Canva, Tilda, and systeme.io) to slip past corporate email filters — 114 observed sessions successfully bypassed email security controls. Clicking the lure routes the victim through a Cloudflare Turnstile (also seen as 'challengepoint' in traffic, alongside reCAPTCHA and hCaptcha as operator-selectable alternatives) anti-bot verification screen intended to filter out sandboxes, crawlers, and automated analysis tools before the fake Microsoft authentication page is rendered. The credential form uses DOMPurify 3.2.6 for client-side sanitization and, on submission, POSTs harvested email/password pairs (in di and pr parameters) to the generation-specific exfiltration endpoint. To increase victim-perceived legitimacy and harvest additional password attempts, the kit displays a fake 'Incorrect Password' message (an #pass-err element) after the first submission, capturing up to three password attempts before redirecting the victim to the legitimate office.com — making the incident appear to the victim as a failed login rather than a successful credential theft. Harvested data is exfiltrated in JSON format via a Telegram bot (api.telegram.org) for real-time, encrypted collection, with some sessions also observed establishing WebSocket connections, which may indicate live credential relaying or adversary-in-the-middle positioning, though this is not fully confirmed.
The Kratos operator admin panel is protected by a master password plus Telegram-based two-factor authentication, and provides operators a dashboard with user/sales statistics, a deploy.* subdomain for rapid stand-up of new phishing domains, choice of a PHP-based Office 365 template or a Node.js reverse proxy with built-in anti-bot capabilities, automated SSL certificate issuance and DNS management, and API endpoints under /vps/* and /domains/* for infrastructure automation — indicating a fully industrialized, subscription-driven cybercrime-as-a-service operation. ANY.RUN attributes a likely Egypt-based operator IP (41.128.0.142) associated with the panel's traffic. Victimology spans more than 20 countries, concentrated in the United States (~33% of observed activity) and Southern Europe (notably Spain), with 148 suspected victim organizations identified via SharePoint tenant-name analysis, spanning SMBs, law firms, schools, polytechnics/educational institutions, industrial firms, manufacturing, technology companies, MSSPs, and public institutions. ANY.RUN's asset-cofingerprinting detection approach (co-occurrence of barr.svg + lg.svg for V1, or dsa.svg + sid.gif + imag.jpg for V2 in the same session) achieves approximately 90% detection recall with near-zero false positives.
MITRE ATT&CK techniques used in TL-2026-1408
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion
Credential Access
T1056 Input Capture; T1110 Brute Force; T1187 Forced Authentication
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Collection
Execution
Impact
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
reconnaissance
T1598 Phishing for Information
stealth
Affected products and versions in Kratos Phishing-as-a-Service Platform Targeting Microsoft
- Microsoft — Microsoft 365 (Entra ID / Office 365 authentication)
Vulnerable versions: cloud service - all tenants susceptible to credential phishing
Fixed in: n/a - social engineering / infrastructure abuse, not a software vulnerability - Adobe — Creative Cloud / Document Cloud (early Kratos lure impersonation)
Vulnerable versions: cloud service - impersonated brand
Fixed in: n/a
Remediation for Kratos Phishing-as-a-Service Platform Targeting Microsoft
Immediate actions
- Block IOC domains (dwbud.vilaribit.com, razen.online, theoceanac.online, jumpast.es, enerdizerandtron.de, klenpare.com, uvarnix.cfd, xavon.sbs, abal.my, starwellmedia.com, aabiz.de, aspireglobal.ltd, buenne.de, dufllot.sbs, espaciocf.de, ihrsupportcenter.de, ilersls.org, aaalen.de, rundwasser.de, smartcontrolengineer.com, sonnenbrillenspot.de, trisrnareprjdocz.com) at email gateway and web proxy
- Block operator IP 41.128.0.142 at perimeter firewall
- Deploy network/proxy detections for co-occurring requests to /assets/img/barr.svg + /assets/img/lg.svg (V1) or *dsa.svg + *sid.gif + *imag.jpg (V2) within a single session
- Alert on POST requests to next.php, nex.php, n3xt.php, officers*eur.php, save.php, or mini.php following external-domain navigation from a Microsoft-branded page
- Force-reset credentials and require MFA re-enrollment for any user who reached an 'Incorrect Password' retry loop on a non-Microsoft-owned domain
Workarounds
- Enable Microsoft 365 Safe Links / Safe Attachments with aggressive re-write-on-click revalidation to catch late-weaponized lure URLs
- Restrict Cloudflare Turnstile / CAPTCHA-gated external links from being auto-rendered in email preview panes
Longer-term hardening
- Deploy phishing-resistant authentication (FIDO2/WebAuthn, certificate-based auth) to neutralize credential-only PhaaS kits
- Adopt behavioral identity analytics / Human Risk Management (HRM) tooling to detect anomalous post-credential sign-in patterns even when credentials are valid
- Ingest curated IOC feeds (e.g., PhishER-style blacklists) directly into Microsoft 365 conditional access and mail-flow rules
- Monitor SharePoint/OneDrive/Forms/Canva/Tilda/systeme.io outbound link-sharing for abuse patterns consistent with lure staging
Weaknesses (CWE) in Kratos Phishing-as-a-Service Platform Targeting Microsoft
CWE-451, CWE-346
Timeline of Kratos Phishing-as-a-Service Platform Targeting Microsoft
- Kratos admin panel first observed active per OSINT/traffic findings, providing operator dashboard, deploy.* subdomain automation, and API endpoints for VPS/domain management.
- Kratos phishing kit (V1/V2 generations) becomes consistently visible in ANY.RUN's Interactive Sandbox, with early campaigns impersonating Adobe Creative Cloud and Document Cloud before pivoting to Microsoft 365.
- V0 generation ('PTT/SOft', Secure File Access lure, dwbud.vilaribit.com, mini.php exfiltration) identified across 9 sandbox sessions — earliest tracked branch of the kit.
- V1 becomes the dominant generation with 1,397 sandbox sessions sharing the barr.svg + lg.svg + ani.gif + res.css + styles.css asset fingerprint and next.php/nex.php/n3xt.php/officers*eur.php exfiltration endpoints.
- V2 generation emerges with 231 sandbox sessions, introducing jQuery 4.0 beta obfuscation, dsa.svg/sid.gif/imag.jpg assets, and fetch()-based save.php exfiltration.
- ANY.RUN develops asset-cofingerprinting detection (co-occurrence of barr.svg+lg.svg for V1, dsa.svg+sid.gif+imag.jpg for V2), retroactively re-attributing 1,484 previously unattributed sandbox sessions to Kratos via a shared SHA-256 styles.css asset connecting 636 tasks.
- Researchers capture and analyze screenshots of the updated attack flow and browser session data showing the harder-to-detect Kratos variant, which replaces the static /SOft URI with common-looking URIs and a more realistic Microsoft-style authentication interface.
- Over 100 analysis sessions of the harder-to-detect campaign variant are documented in ANY.RUN's Interactive Sandbox within a single week, showing rising activity across Europe and targeting manufacturing, technology, and MSSP organizations.
- ANY.RUN publishes consolidated research (via Cyber Security News, Medium, CyberPress, and KnowBe4 coverage) attributing 1,628 combined V1/V2 sandbox sessions, 148 suspected victim organizations across 20+ countries, and 114 confirmed email-filter bypasses to Kratos.
Sources cited for Kratos Phishing-as-a-Service Platform Targeting Microsoft
- Kratos PhaaS Attacking Microsoft 365 Users
- Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
- New Kratos PhaaS Campaign Attack Organizations with a Harder-to-Detect Phishing Flow
- The Rise of Kratos: How the New Phishing-as-a-Service Kit Industrializes Cybercrime
- Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit
Threats related to Kratos Phishing-as-a-Service Platform Targeting Microsoft
- International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting Millions of SBA Loan Applicants
- LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing) for Credential Theft
- EvilTokens/ARToken Device-Code Phishing Kit Bypasses MFA to Compromise Microsoft 365 Accounts
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
Detection coverage for TL-2026-1408
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1408 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1408
8 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.