Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials
ID: a9acf512-e9f2-585f-b812-21387790fecb
STIX ID: report--a9acf512-e9f2-585f-b812-21387790fecb
Feed Name: Cyber Press
Threat Score
Kratos is a commercial phishing kit observed in sandbox telemetry since Jan 2026 that uses layered redirect chains through trusted services and anti-bot systems (e.g., Cloudflare Turnstile) to present convincing Microsoft login clones and collect enterprise credentials via PHP endpoints; researchers identified multiple generations (V0–V2), specific collection paths (next.php, save.php, etc.), WebSocket usage, and asset-based IOCs to detect and hunt the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
