Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe — Threadlinqs Intelligence
As of 2026-07-16, Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-1408 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Kratos is an actively evolving phishing-as-a-service (PhaaS) kit that impersonates Microsoft 365 (and formerly Adobe Creative Cloud/Document Cloud) login flows, using Cloudflare
Kratos is a subscription-based Phishing-as-a-Service (PhaaS) platform first observed operating an admin panel since at least September 10, 2025, with its phishing kit visible in ANY.RUN's Interactive Sandbox from January 2026 onward and continued activity through the July 2026 reporting window. The kit has evolved across at least three tracked generations: V0 ('PTT/SOft', a 'Secure File Access' lure with blurred invoice background, exfiltrating to mini.php under a /PTT/SOft/ path, seen on the dwbud.vilaribit.com domain and associated with only 9 sandbox sessions); V1 (the dominant generation with 1,397 identified sandbox sessions, using a shared asset fingerprint of barr.svg + lg.svg + ani.gif + res.css + styles.css, a fake Microsoft sign-in page with an animated envelope and 'Loading in progress...' splash screen, and exfiltration to next.php/nex.php/n3xt.php/officers*eur.php); and V2 (the current generation, 231 sessions, using dsa.svg + sid.gif + imag.jpg + main.js assets, jQuery 4.0 beta with obfuscated JavaScript, and exfiltration via fetch() calls to save.php). Across V1 and V2 combined, ANY.RUN identified 1,628 sandbox sessions, of which only 156 had previously been manually attributed to Kratos and 1,484 were previously unattributed to any known family — with a distinct SHA-256 shared styles.css asset connecting 636 of those tasks. A separate, harder-to-detect campaign variant observed roughly 100+ analysis sessions in a single week, replacing the static /SOft URI and 'Secure Document Access' branding with common-looking URIs and a more realistic Microsoft-style authentication interface targeting manufacturing, technology, and MSSP organizations.
The attack chain begins with phishing emails using document-share, invoice-review, and DocuSign-pending-action lures, frequently staged through legitimate cloud services (SharePoint/OneDrive account for 351 observed delivery tasks, alongside Microsoft Forms, Canva, Tilda, and systeme.io) to slip past corporate email filters — 114 observed sessions successfully bypassed email security controls. Clicking the lure routes the victim through a Cloudflare Turnstile (also seen as 'challengepoint' in traffic, alongside reCAPTCHA and hCaptcha as operator-selectable alternatives) anti-bot verification screen intended to filter out sandboxes, crawlers, and automated analysis tools before the fake Microsoft authentication page is rendered. The credential form uses DOMPurify 3.2.6 for client-side sanitization and, on submission, POSTs harvested email/password pairs (in di and pr parameters) to the generation-specific exfiltration endpoint. To increase victim-perceived legitimacy and harvest additional password attempts, the kit displays a fake 'Incorrect Password' message (an #pass-err element) after the first submission, capturing up to three password attempts before redirecting the victim to the legitimate office.com — making the incident appear to the victim as a failed login rather than a successful credential theft. Harvested data is exfiltrated in JSON format via a Telegram bot (api.telegram.org) for real-time, encrypted collection, with some sessions also observed establishing WebSocket connections, which may indicate live credential relaying or adversary-in-the-middle positioning, though this is not fully confirmed.
The Kratos operator admin panel is protected by a master password plus Telegram-based two-factor authentication, and provides operators a dashboard with user/sales statistics, a deploy.* subdomain for rapid stand-up of new phishing domains, choice of a PHP-based Office 365 template or a Node.js reverse proxy with built-in anti-bot capabilities, automated SSL certificate issuance and DNS management, and API endpoints under /vps/* and /domains/* for infrastructure automation — indicating a fully industrialized, subscription-driven cybercrime-as-a-service operation. ANY.RUN attributes a likely Egypt-based operator IP (41.128.0.142) associated with the panel's traffic. Vi
Weaknesses (CWE)
CWE-451, CWE-346
Target sectors: small business, legal, education, manufacturing, industrial, technology, msp mssp, government administration, public sector
Target regions: united states of america, spain, 039 - Southern Europe, Europe, Global (20+ countries)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
8 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1583, T1583, T1587, T1585, T1566, T1598, T1204, T1497