logo

Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials

ID: 8938c700-001d-508a-a92c-6731d0d037c0

STIX ID: report--8938c700-001d-508a-a92c-6731d0d037c0

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Tushar Subhra Dutta

...
...

Kratos is a phishing-as-a-service operation targeting Microsoft 365 users across the United States, Europe, and other regions by luring victims with believable document, invoice, and file-sharing messages that redirect through trusted services to fake Microsoft login pages; the kit uses Cloudflare Turnstile anti-bot checks, rotating domains, and possible WebSocket-based AiTM relaying. The report documents multiple Kratos versions, provides IoCs (file assets, exfiltration scripts, associated domains, an IP, and a shared styles.css SHA-256), shows evidence of active sessions in sandboxes, and gives detection and response recommendations including password resets, session revocation, and threat-hunting signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.