logo

Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials

ID: a9acf512-e9f2-585f-b812-21387790fecb

STIX ID: report--a9acf512-e9f2-585f-b812-21387790fecb

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Varshini

...
...

Kratos is a commercial phishing kit observed in sandbox telemetry since Jan 2026 that uses layered redirect chains through trusted services and anti-bot systems (e.g., Cloudflare Turnstile) to present convincing Microsoft login clones and collect enterprise credentials via PHP endpoints; researchers identified multiple generations (V0–V2), specific collection paths (next.php, save.php, etc.), WebSocket usage, and asset-based IOCs to detect and hunt the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.