logo

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

ID: c34845f9-8d99-500f-97a0-991c3e4828f1

STIX ID: report--c34845f9-8d99-500f-97a0-991c3e4828f1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

Kratos is a subscription-based phishing-as-a-service platform actively used to target Microsoft 365 users across the US, Europe, and beyond by embedding malicious links in legitimate document-sharing workflows (SharePoint, OneDrive, Forms, Canva, etc.). ANY.RUN analysis linked 1,628 sandbox sessions to multiple Kratos variants (V0, V1, V2) that use anti-bot verification (Cloudflare Turnstile/reCAPTCHA/hCaptcha), fake Microsoft login pages, and distinct asset fingerprints (e.g., barr.svg + lg.svg) to harvest credentials; stolen data enables business email compromise, invoice fraud, and data theft. The report lists IOC domains/IPs, highlights detection and hunting signals (paired asset requests, POSTs to next.php/save.php, Turnstile precedents, WebSocket use), and recommends immediate remediation steps (revoke sessions/tokens, reset passwords, inspect OAuth grants and mailbox rules, review SharePoint/OneDrive access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.