Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials
ID: 8938c700-001d-508a-a92c-6731d0d037c0
STIX ID: report--8938c700-001d-508a-a92c-6731d0d037c0
Feed Name: cybersecurityNews.com
Kratos is a phishing-as-a-service operation targeting Microsoft 365 users across the United States, Europe, and other regions by luring victims with believable document, invoice, and file-sharing messages that redirect through trusted services to fake Microsoft login pages; the kit uses Cloudflare Turnstile anti-bot checks, rotating domains, and possible WebSocket-based AiTM relaying. The report documents multiple Kratos versions, provides IoCs (file assets, exfiltration scripts, associated domains, an IP, and a shared styles.css SHA-256), shows evidence of active sessions in sandboxes, and gives detection and response recommendations including password resets, session revocation, and threat-hunting signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
