Kratos Phishing as a Service Targets US and EU to Reduce Microsoft 365 Account Takeover Risk

The latest threat report from Any Run, published on July 20, 2026, exposes the evolution of Kratos – a mature phishing‑as‑a‑service (PhaaS) operation that focuses on Microsoft 365 users across the United States and Europe. By marrying trusted platforms, sophisticated anti‑bot checks, and convincing login pages, Kratos steals credentials while delaying detection and response. The result is higher risk of account takeover, fraud, data exposure, and increased incident response costs.

Threat Overview

Kratos operates as a turnkey phishing kit sold through a subscription model. Analyst work in the Any Run sandbox revealed three distinct generations (V0, V1, and V2), each with its own exfiltration code but all sharing the same operator panel. The researchers traced 1,484 previously unattributed detonations, mapping infrastructure, operator panels, and victim patterns.

Targeted Industries and Geography

The kit has been observed targeting organizations in more than 20 countries, with a strong concentration in the US, Spain, and Southern Europe. Victim sectors include SMBs, law firms, schools, industrial groups, and other small‑to‑medium enterprises.

Geographic Distribution of Sessions

  • Spain (.es, .cat, .eus): 171 sessions
  • International TLDs (.com, .org, .net): ~162 sessions
  • France: 31 sessions
  • Sweden: 15 sessions
  • Austria: 11 sessions
  • Portugal: 10 sessions
  • Italy, Germany, Norway, Slovenia, Belgium: 4–5 each

Attack Chain

The typical attack flow begins with a phishing email that often bypasses corporate filters. Common subject lines include:

  • “User N has shared a document with you”
  • “Sign the document via DocuSign”
  • “An invoice has been sent”

The email links to legitimate services such as Microsoft SharePoint, OneDrive, Canva, Tilda, systeme.io, or Microsoft Forms. After a short redirect, victims reach the Kratos phishing page where they are presented with an animated envelope and the message “Loading in progress…” over a blurred invoice.

Victims are then asked to prove they are not bots using Cloudflare Turnstile. Once verified, the fake Microsoft 365 login form appears. Credentials are harvested via POST requests to version‑specific endpoints (next.php for V1, save.php for V2, mini.php for V0). The victim has only three password attempts before being redirected or shown an error.

Indicators of Compromise

Asset Fingerprints:

  • V1: requests to /assets/img/barr.svg and /assets/img/lg.svg
  • V2: requests to dsa.svg, sid.gif, and imag.jpg

Content Hashes (case‑insensitive):

  • lg.svg – cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5ea
  • barr.svg – 949895df17148c5ea29f190d2619a14b3ec648425b9cc3c5a1423553c16f3898
  • ani.gif – 9d1a1e3b5b5de8a6c76ded7a01fa01709d426232b0048c9ee6ba0c5c1b8b42
  • styles.css – c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebb

Exfiltration Endpoints:

  • V0: /SOft/mini.php
  • V1: /next.php, /nex.php, /n3xt.php, /officers*eur.php
  • V2: /save.php

Behavioral Indicators:

  • Cloudflare Turnstile challenge before login form
  • Animated envelope “Loading in progress…” overlay
  • Page title “Authentication” or similar
  • Limited password attempts (max 3)
  • WebSocket activity present in some sessions

Detection Methods

Security teams can leverage a combination of the following:

  • Asset Fingerprints: Monitor for simultaneous requests to barr.svg & lg.svg (V1) or dsa.svg, sid.gif & imag.jpg (V2).
  • Hash Matching: Compare downloaded assets against the known SHA256 values.
  • Endpoint Monitoring: Detect POST traffic to next.php, save.php, or mini.php from internal hosts.
  • Engine Signatures: Use Any Run signatures such as “Kratos related URL chain observed” and “Kratos exfil activity observed.”
  • Browser‑Level Investigation: Inspect page code for submitData() logic, redirect URLs, and credential handling.
  • Behavioral Scoring: Apply cumulative scores (e.g., +80 for asset fingerprint, +35 for endpoint match) to assess confidence.

Response Recommendations

  • Adopt a tiered response: reset passwords for basic credential harvesters; revoke sessions and refresh tokens for confirmed or likely AiTM activity.
  • Block disposable attacker domains (.horse, .cfd, .sbs, etc.) but review shared parent domains before blanket blocking.
  • Report compromised legitimate sites instead of outright blocking to reduce business impact.
  • Monitor Cloudflare edge infrastructure and broad ASNs rather than blocking them.
  • Train users on phishing link analysis; encourage reporting suspicious emails for rapid investigation.
  • Leverage Any Run interactive sandbox for safe link analysis, never input real credentials during testing.

Recommendations for CISOs and SOC Leaders

  • Measure time to confident attribution, not just detection.
  • Add browser‑level investigation to phishing workflows.
  • Create distinct playbooks for credential harvesting vs. AiTM scenarios.
  • Turn Kratos indicators into repeatable controls: asset fingerprints, hashes, exfiltration endpoints, and confidence scoring should be embedded in SIEM/SOAR hunting rules.
  • Avoid broad infrastructure blocking; target specific malicious assets to preserve legitimate traffic.

Conclusion

Kratos demonstrates how a single stolen Microsoft 365 account can spiral into wider business risk. By combining sandbox analysis, browser‑level evidence, and family‑level attribution, defenders can detect the kit earlier, link related activity, and respond with greater confidence. The result is reduced investigation time, minimized disruption to legitimate services, and containment of account compromise before it escalates into a larger incident.

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading