Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
Kratos is a mature Phishing-as-a-Service operation impersonating Microsoft 365 login pages to steal credentials across US and European organizations. The kit uses legitimate platforms (SharePoint, Canva, Tilda) as intermediary redirect pages, Cloudflare Turnstile to block automated analysis, and PHP endpoints for credential exfiltration. Researchers identified three generations (V0, V1, V2) with distinct asset fingerprints and exfiltration code, and uncovered the operator panel with automated deployment, Telegram-based data delivery, and geographic restriction capabilities.
- domainaaalen[.]deKratos-associated German domain from IOC list
- domainaabiz[.]deKratos-associated German domain, likely compromised legitimate site serving phishing content
- domainabal[.]myKratos-associated phishing domain from IOC list
- domainaspireglobal[.]ltdKratos-associated phishing domain from IOC list
- domainbuenne[.]deKratos-associated German domain from IOC list
- domaincrm-technik[.]deShared parent domain associated with Kratos infrastructure, may also host legitimate subdomains
- domaindufllot[.]sbsKratos disposable phishing domain on low-cost TLD
- domaindwbud[.]vilaribit[.]comEarly V0 Kratos phishing domain hosting /PTT/SOft/ credential harvesting page with Secure File Access lure
- domainenerdizerandtron[.]deKratos domain serving both V1 and V2 phishing pages
- domainespaciocf[.]deKratos-associated German domain from IOC list
- domainfkrekoloba[.]comActive Kratos phishing domain observed in sandbox analysis serving fake Microsoft 365 login page with Cloudflare Turnstile protection
- domainihrsupportcenter[.]deKratos-associated German domain from IOC list
- domainilersls[.]orgKratos-associated phishing domain from IOC list
- domainjumpast[.]esKratos domain serving both V1 and V2 phishing pages, Spanish TLD
- domainklenpare[.]comWildcard Kratos domain rotating through randomly generated subdomains
- domainpag[.]pleacefactudocu[.]onlineKratos phishing domain with Spanish-themed factura lure path, observed in sandbox network analysis
- domainrazen[.]onlineKratos domain serving both V1 and V2 phishing pages
- domainrundwasser[.]deKratos-associated German domain from IOC list
- domainsmartcontrolengineer[.]comKratos-associated phishing domain from IOC list
- domainsonnenbrillenspot[.]deCompromised legitimate German website serving Kratos phishing page at /delikfacturewashd/ path
- domainstarwellmedia[.]comKratos-associated phishing domain from IOC list
- domaintheoceanac[.]onlineKratos domain serving both V1 and V2 phishing pages
- domaintransfeergo[.]comKratos phishing domain hosting V2 login page with obfuscated JavaScript exfiltration to save.php
- domaintrisrnareprjdocz[.]comKratos-associated phishing domain from IOC list
- domainuvarnix[.]cfdWildcard Kratos domain on low-cost TLD rotating through random subdomains
- domainxavon[.]sbsWildcard Kratos domain on low-cost TLD rotating through random subdomains
- ip41[.]128[.]0[.]142Operator IP address (Egypt) associated with Kratos admin panel infrastructure
- ip51[.]116[.]253[.]168Server IP observed in Kratos phishing session network analysis associated with pag.pleacefactudocu.online, likely Azure-hosted phishing infrastructure
- sha256949895df17148c5ea29f190d2619a14b3ec648425b9cc3c5a1423553c16f3898Content hash of barr.svg asset file, primary Kratos V1 fingerprint that almost always appears alongside lg.svg
- sha2569d1a1a5e3b5e5de8a6c76ded7a01fa01709d426232b0048c9ee6ba0c5c1b8b42Content hash of ani.gif asset file, V2 generation fingerprint used alongside dsa.svg and sid.gif for Kratos identification
- sha256a3c298ccf2456989ceb080e661b01c3b00445902ae7bb3e58dad4d846334ff9cV2 asset content hash used in Kratos V2 TI Lookup queries for identification
- sha256c447e75f1029ed7a5882add16bcd13ad44be3bd47c93c830ff39185e23d25ebbContent hash of styles.css file loaded by fake Microsoft Sign In page, connects 636 tasks across V1 and V2 generations
- sha256cd231b895bbcd7154b81df1e065bf02f1ec667b920c8b6d23308cd509833b5eaContent hash of lg.svg asset file, primary Kratos V1 fingerprint providing 90% recall with near-zero false positives; also byte-for-byte identical to dsa.svg in V2
- urlhxxps://dwbud[.]vilaribit[.]com/PTT/SOft/V0 Kratos phishing page URL with Secure File Access credential harvesting lure
- urlhxxps://fkrekoloba[.]com/ut/prKratos phishing page URL serving fake Microsoft 365 login with Cloudflare Turnstile and credential exfiltration to next.php
- urlhxxps://pag[.]pleacefactudocu[.]online/pfactura/assets/bootstrap/css/bootstrap[.]min[.]cssBootstrap CSS asset loaded by Kratos phishing page at /pfactura/ path on pleacefactudocu.online
- urlhxxps://sonnenbrillenspot[.]de/delikfacturewashd/Kratos phishing page on compromised legitimate German website with fake Microsoft 365 login
- urlhxxps://transfeergo[.]com/pdff/Kratos V2 phishing page URL with fake Microsoft 365 Sign In overlay on blurred PDF document
Detection / Hunteropenrouter
What Happened
A criminal service called Kratos is being used to steal Microsoft 365 login credentials from organizations in the United States and Europe. Attackers send emails that appear to be about shared documents or invoices, then redirect victims to fake Microsoft login pages that look very realistic. If attackers gain access to an account, simply changing the password may not be enough to remove them because they may have stolen the active login session. Organizations should train employees to recognize suspicious emails, ensure multi-factor authentication is enabled, and have procedures ready to revoke active sessions if an account is compromised. Security teams should look for specific technical indicators like the files barr.svg and lg.svg appearing together on phishing pages.
Key Takeaways
- Kratos is a mature PhaaS platform with three generations (V0, V1, V2), each with distinct exfiltration endpoints and asset fingerprints
- Asset fingerprint using barr.svg + lg.svg provides 90% recall with near-zero false positive rate for V1 detection
- Operator panel discovered via favicon OSINT, active since September 2025, with automated VPS deployment, Telegram-based exfiltration, and anti-bot configuration
- 1,628 sandbox sessions identified across 148 suspected victim organizations in 20+ countries, concentrated in US and Spain
- Kratos shares VPS infrastructure with other phishing kits (Tycoon, Flowerstorm, Sneaky2FA, EvilProxy) but maintains distinct code and asset patterns
Affected Systems
- Microsoft 365 accounts
- Microsoft SharePoint
- Microsoft OneDrive
- Microsoft Exchange Online
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Phishing email with document/invoice-themed lure bypasses corporate email filters and secure email gateways
- Trust-building: Victim clicks link to legitimate service (SharePoint, OneDrive, Canva, Tilda) serving as intermediary redirect page
- Redirection: Victim is redirected from legitimate platform to Kratos phishing infrastructure on disposable or compromised domains
- Evasion: Cloudflare Turnstile CAPTCHA challenge blocks automated scanners and security sandboxes from reaching the phishing page
- Credential Theft: Fake Microsoft 365 login page displays animated envelope Loading in progress message then captures credentials via POST to PHP endpoint (next.php/save.php/mini.php)
- Exfiltration: Stolen credentials packaged as JSON and sent to attacker Telegram channel; WebSocket connections may indicate AiTM session relaying
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: ANY.RUN sandbox engine signatures
The article describes ANY.RUN sandbox signatures for Kratos (e.g., Kratos related URL chain observed, Kratos exfil activity observed) and a SIEM scoring model with weighted indicators. It references ELK queries in an accompanying README but does not include actual rule bodies or query syntax in the article text.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | Kratos operates entirely within the browser context. EDR can observe browser process activity and network connections but cannot inspect credential submission to fake login pages or DOM-level JavaScript execution such as the submitData() function. |
| Network Visibility | Medium | Web proxy and DNS logs can identify HTTP requests to Kratos asset fingerprints (barr.svg, lg.svg), POST requests to exfiltration endpoints (next.php, save.php), and connections to known phishing domains. However, Cloudflare CDN proxying obscures origin infrastructure. |
| Detection Difficulty | Moderate | The asset fingerprint (barr.svg + lg.svg) provides 90% recall with near-zero false positives, but the kit rotates domains rapidly on low-cost TLDs, uses Cloudflare to proxy traffic, and V2 introduces code obfuscation requiring browser-level analysis. |
Required Log Sources
- Web proxy logs
- DNS query logs
- Email gateway logs
- Microsoft 365 audit logs
- Azure AD sign-in logs
- Cloudflare WAF or edge logs
- Network firewall logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for HTTP requests to both barr.svg and lg.svg within the same browsing session, as this asset pair is the primary Kratos V1 fingerprint with 90% recall and near-zero false positives. | Web proxy logs, SWG logs, network traffic analysis | Credential Theft | Very Low - the article states this fingerprint has a false-positive rate close to zero in negative-control testing. |
| Search for POST requests to PHP endpoints named next.php, save.php, nex.php, n3xt.php, or officers*eur.php from corporate networks, as these are Kratos credential exfiltration endpoints. | Web proxy logs, network IPS/IDS, firewall logs | Exfiltration | Low to Medium - these are common PHP filenames that could appear on legitimate web applications, but POST requests with credential parameters to external domains are suspicious. |
| Look for browser sessions where Cloudflare Turnstile challenge appears before a Microsoft 365 login page on non-Microsoft domains, as Kratos uses this to block automated scanners. | Web proxy logs, SWG logs, DNS logs | Defense Evasion | Low - Cloudflare Turnstile before a Microsoft login page on a non-Microsoft domain is highly suspicious. |
| Hunt for file downloads matching the SHA256 hashes of lg.svg, barr.svg, styles.css, or ani.gif, as these content hashes remain stable even when filenames change across Kratos generations. | Web proxy logs with content hashing, network DLP, sandbox analysis | Credential Theft | Very Low - specific content hashes are unlikely to appear in legitimate traffic. |
| Monitor for WebSocket connections established during what appears to be a Microsoft 365 authentication flow on non-Microsoft domains, as this may indicate AiTM credential relaying activity. | Network traffic analysis, web proxy logs with WebSocket visibility | Credential Theft | Medium - WebSocket connections alone do not prove session theft; legitimate applications may use WebSockets during authentication flows. |
Control Gaps
- Email gateways may not block phishing emails using legitimate intermediary platforms (SharePoint, Canva, Tilda) as redirect chains
- Domain-based blocking is ineffective due to rapid domain rotation on low-cost TLDs and use of compromised legitimate sites
- Cloudflare CDN proxying obscures origin IP infrastructure and prevents direct IP-based blocking
- Static URL analysis cannot detect obfuscated V2 JavaScript exfiltration logic without browser-level execution
- Password reset alone is insufficient if session tokens were stolen via AiTM; session and refresh token revocation is required
Key Behavioral Indicators
- HTTP requests to both /assets/img/barr.svg and /assets/img/lg.svg from same browser session (V1 fingerprint)
- HTTP requests to dsa.svg, sid.gif, and imag.jpg from same session (V2 fingerprint)
- POST requests to PHP endpoints (next.php, save.php, nex.php, n3xt.php, officers*eur.php, mini.php) from browser sessions
- Page titled Authentication on non-Microsoft domains displaying Microsoft 365 login form
- Cloudflare Turnstile challenge appearing before Microsoft login form on non-Microsoft domains
- Animated envelope with Loading in progress message before login form display
- WebSocket connections during Microsoft 365 authentication flows on non-Microsoft domains
- Redirect chains from legitimate services (SharePoint, Canva, Tilda, systeme.io) to non-Microsoft domains
- Email subjects containing shared a document, Sign the document via DocuSign, or An invoice has been sent with links to non-Microsoft domains
False Positive Assessment
Low - The primary Kratos fingerprint (barr.svg + lg.svg appearing together) provides 90% recall with a false-positive rate close to zero in negative-control testing. Content hashes for asset files remain stable across domain rotations. The SIEM scoring model includes negative indicators (-80 for tags associated with other kits like Stealc, Vidar, Tycoon, or Sneaky2FA) to reduce cross-attribution errors.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. For confirmed Kratos phishing, reset compromised user passwords and revoke active sessions and refresh tokens if AiTM activity is suspected.
- Consider blocking known Kratos disposable domains on low-cost TLDs (.horse, .cfd, .sbs, .today, .fit, .online) at your web proxy or firewall, prioritizing domains from the IOC list.
- Evaluate whether shared parent domains (klenpare.com, uvarnix.cfd, xavon.sbs, crm-technik.de) should be blocked after reviewing for legitimate subdomains to avoid business disruption.
- Consider adding Kratos asset fingerprints (barr.svg, lg.svg, dsa.svg) and exfiltration endpoint patterns (next.php, save.php, mini.php) to your web proxy block lists and SIEM detection rules.
Infrastructure Hardening
- Consider implementing the cumulative SIEM scoring model described in the article for confidence-level attribution rather than binary IOC matching.
- If your organization uses Microsoft 365, consider enabling Conditional Access policies requiring compliant devices or trusted locations for authentication.
- Evaluate whether your email security gateway can detect and flag redirect chains through legitimate platforms (SharePoint, Canva, Tilda, systeme.io) to suspicious external domains.
- Consider monitoring Cloudflare edge IP ranges and challengepoint requests as risk indicators rather than blocking them outright.
User Protection
- If supported by your identity provider, consider enforcing FIDO2 hardware key authentication which is resistant to adversary-in-the-middle attacks.
- Evaluate deploying browser-based phishing protection that can inspect DOM changes and JavaScript execution patterns on login pages.
- Consider implementing session timeout policies and requiring reauthentication for sensitive actions within Microsoft 365.
Security Awareness
- Consider incorporating Kratos phishing email patterns into existing awareness training, particularly document-sharing and invoice-themed lures.
- Remind employees that Microsoft login pages should only appear on microsoft.com domains and to report any authentication prompts on unfamiliar domains.
- Encourage employees to submit suspicious links to the security team for analysis rather than clicking them, and provide a simple reporting mechanism.
MITRE ATT&CK Mapping
Initial Access
Stealth
Credential Access
Lateral Movement
Additional IOCs
- Ips:
51[.]116[.]253[.]168- Server IP observed in Kratos phishing session network analysis associated with pag.pleacefactudocu.online, likely Azure-hosted phishing infrastructure
- Domains:
abal[.]my- Kratos-associated phishing domain from IOC liststarwellmedia[.]com- Kratos-associated phishing domain from IOC listaabiz[.]de- Kratos-associated German domain, likely compromised legitimate site serving phishing contentaspireglobal[.]ltd- Kratos-associated phishing domain from IOC listbuenne[.]de- Kratos-associated German domain from IOC listdufllot[.]sbs- Kratos disposable phishing domain on low-cost TLDenerdizerandtron[.]de- Kratos domain serving both V1 and V2 phishing pagesespaciocf[.]de- Kratos-associated German domain from IOC listihrsupportcenter[.]de- Kratos-associated German domain from IOC listilersls[.]org- Kratos-associated phishing domain from IOC listaaalen[.]de- Kratos-associated German domain from IOC listrundwasser[.]de- Kratos-associated German domain from IOC listsmartcontrolengineer[.]com- Kratos-associated phishing domain from IOC listtrisrnareprjdocz[.]com- Kratos-associated phishing domain from IOC listklenpare[.]com- Wildcard Kratos domain rotating through randomly generated subdomainsuvarnix[.]cfd- Wildcard Kratos domain on low-cost TLD rotating through random subdomainsxavon[.]sbs- Wildcard Kratos domain on low-cost TLD rotating through random subdomainsrazen[.]online- Kratos domain serving both V1 and V2 phishing pagestheoceanac[.]online- Kratos domain serving both V1 and V2 phishing pagesjumpast[.]es- Kratos domain serving both V1 and V2 phishing pages, Spanish TLDcrm-technik[.]de- Shared parent domain associated with Kratos infrastructure, may also host legitimate subdomains
- Urls:
hxxps://fkrekoloba[.]com/ut/pr- Kratos phishing page URL serving fake Microsoft 365 login with Cloudflare Turnstile and credential exfiltration to next.phphxxps://dwbud[.]vilaribit[.]com/PTT/SOft/- V0 Kratos phishing page URL with Secure File Access credential harvesting lurehxxps://transfeergo[.]com/pdff/- Kratos V2 phishing page URL with fake Microsoft 365 Sign In overlay on blurred PDF documenthxxps://sonnenbrillenspot[.]de/delikfacturewashd/- Kratos phishing page on compromised legitimate German website with fake Microsoft 365 loginhxxps://pag[.]pleacefactudocu[.]online/pfactura/assets/bootstrap/css/bootstrap.min.css- Bootstrap CSS asset loaded by Kratos phishing page at /pfactura/ path on pleacefactudocu.online
- File Hashes:
a3c298ccf2456989ceb080e661b01c3b00445902ae7bb3e58dad4d846334ff9c(SHA256) - V2 asset content hash used in Kratos V2 TI Lookup queries for identification
- Other:
*/assets/img/barr.svg- Kratos V1 asset fingerprint URL path, primary detection indicator when observed alongside lg.svg*/assets/img/lg.svg- Kratos V1 asset fingerprint URL path, primary detection indicator when observed alongside barr.svg*/next.php- Kratos V1 credential exfiltration PHP endpoint receiving POST requests with di and pr parameters*/save.php- Kratos V2 credential exfiltration PHP endpoint*/nex.php- Kratos V1 credential exfiltration endpoint variant*/n3xt.php- Kratos V1 credential exfiltration endpoint variant*/officers*eur.php- Kratos V1 credential exfiltration endpoint variant*/PTT/SOft/mini.php- Kratos V0 credential exfiltration endpoint using sendDataToPHP() function