ANY.RUN researchers say the Kratos phishing-as-a-service operation is actively impersonating Microsoft 365 sign-in pages, with a pair of page assets—
The vendor’s July 2026 research attributes 1,484 previously unclassified sandbox sessions to Kratos, alongside 156 sessions already labeled as the family. The operation targets organizations in the United States and Europe, delivering document and invoice lures through trusted services before sending victims to fake Microsoft authentication pages.
Kratos V1 pages commonly load
A newer V2 branch uses
For proxy, DNS, secure web gateway, and sandbox telemetry, the best initial hunt is a correlated one: look for the V1 or V2 asset sets and then check for a subsequent POST to a matching exfiltration endpoint. A standalone
For a likely credential-harvesting incident, reset the password, review MFA methods and registration changes, and examine recent mailbox, SharePoint, OneDrive, and sign-in activity. For suspected token or session theft, Microsoft’s Entra guidance calls for blocking new sign-ins and revoking the affected user’s sessions and refresh tokens; simply changing a password may leave a valid application session usable until it expires.
A sensible SOC rule can assign high confidence when it sees either complete Kratos asset family, add confidence for matching content hashes or a POST to
Kratos is a reminder that Microsoft 365 phishing defense cannot end at email filtering: analysts need enough browser and network visibility to distinguish a blocked lure from a credential capture—and to escalate immediately when the evidence points to session theft.
barr.svg and lg.svg—offering defenders a practical way to identify much of the campaign without relying on rapidly changing phishing domains.The vendor’s July 2026 research attributes 1,484 previously unclassified sandbox sessions to Kratos, alongside 156 sessions already labeled as the family. The operation targets organizations in the United States and Europe, delivering document and invoice lures through trusted services before sending victims to fake Microsoft authentication pages.
The useful detection signal is in the page assets
Kratos V1 pages commonly load barr.svg, lg.svg, ani.gif, res.css, and styles.css; ANY.RUN found the first two assets together in 1,397 sessions. That pairing is more actionable than a domain-only blocklist because affiliates can rotate domains or compromise legitimate sites while retaining the kit’s underlying files.A newer V2 branch uses
dsa.svg, sid.gif, and imag.jpg, while the older V0 branch used /PTT/SOft/ paths and posted captured data to mini.php. The V1 credential-harvesting flow typically submits data to next.php, with observed filename variants including nex.php, n3xt.php, and officers*eur.php; V2 uses save.php.For proxy, DNS, secure web gateway, and sandbox telemetry, the best initial hunt is a correlated one: look for the V1 or V2 asset sets and then check for a subsequent POST to a matching exfiltration endpoint. A standalone
next.php request is not enough to prove Kratos, but the assets-plus-exfiltration combination materially improves confidence.A password reset may be insufficient
Kratos pages reportedly use Cloudflare Turnstile and resemble Microsoft’s sign-in experience closely enough to frustrate automated scanners and hurried users. Some analyzed sessions also opened WebSocket connections. That alone does not establish adversary-in-the-middle session theft, but it is a reason to investigate whether an attacker obtained a session or refresh token rather than only a password.For a likely credential-harvesting incident, reset the password, review MFA methods and registration changes, and examine recent mailbox, SharePoint, OneDrive, and sign-in activity. For suspected token or session theft, Microsoft’s Entra guidance calls for blocking new sign-ins and revoking the affected user’s sessions and refresh tokens; simply changing a password may leave a valid application session usable until it expires.
Put the indicators into an M365 response workflow
Microsoft recommends Standard or Strict preset security policies in Defender for Office 365, which can apply Safe Links, Safe Attachments, and more aggressive anti-phishing controls. Administrators should also verify spoof and impersonation protection, especially where third-party email gateways or custom mail-routing connectors are involved.A sensible SOC rule can assign high confidence when it sees either complete Kratos asset family, add confidence for matching content hashes or a POST to
next.php or save.php, and downgrade alerts when the same session shows distinct indicators of another phishing kit. That avoids turning shared Cloudflare infrastructure, cloud-hosting IPs, or compromised websites into noisy blanket blocks.Kratos is a reminder that Microsoft 365 phishing defense cannot end at email filtering: analysts need enough browser and network visibility to distinguish a blocked lure from a credential capture—and to escalate immediately when the evidence points to session theft.
References
- Primary source: HackerNoon
Published: 2026-07-28T00:00:00+00:00
Loading…
hackernoon.com - Related coverage: any.run
Loading…
any.run - Related coverage: medium.com
Loading…
medium.com - Related coverage: vpncentral.com
Loading…
vpncentral.com - Related coverage: secnews.gr
Loading…
www.secnews.gr - Related coverage: cyfar.ca
Loading…
cyfar.ca