Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials

The kit combines trusted cloud services, Cloudflare Turnstile challenges, convincing Microsoft login clones, and PHP-based credential collection endpoints to evade detection and steal enterprise credentials.

The operation has been active in ANY.RUN sandbox telemetry since January 2026, while its operator panel appears to have existed since at least September 2025.

Researchers identified 1,6281{,}6281,628 sandbox sessions tied to its main variants. Only 156156156 sessions had previously been tagged as Kratos, leaving 1,4841{,}4841,484 newly attributed detections.

Kratos is sold as a turnkey platform that lets affiliates deploy phishing pages, configure delivery of stolen data through Telegram or email, add geographic restrictions, and select anti-bot systems such as Cloudflare Turnstile, reCAPTCHA, or hCaptcha.

The main target is Microsoft 365. Researchers observed 1,3651{,}3651,365 sessions redirecting victims to pages impersonating login.live.com or microsoftonline.com.

Attackers often use document-sharing and invoice-themed lures, including messages such as “User N has shared a document with you,” “Sign the document via DocuSign,” and “An invoice has been sent.”

Phishing email targeting company employees  (Source: any.run)
Phishing email targeting company employees (Source: any.run)

Many campaigns first direct victims through trusted services, including SharePoint, OneDrive, Canva, Microsoft Forms, Tilda, and systeme.io.

This layered redirect chain can help malicious links pass email security tools. In 114114114 observed cases, phishing emails had already passed corporate email filters or secure email gateways before analysts submitted them to the sandbox.

Kratos Credential Theft Infrastructure

After reaching the phishing site, victims may face a Cloudflare Turnstile prompt asking them to prove they are not bots. This adds legitimacy while filtering automated scanners, sandbox systems, and security crawlers.

Kratos pages commonly show an animated envelope over a blurred document or invoice, then display a counterfeit Microsoft sign-in form.

The screen carries the phrase “Loading in progress…” and the browser tab is frequently titled “Authentication.”

The kit has evolved through three generations. The early V0 branch used the path /PTT/SOft/mini.php to collect data.

The dominant V1 generation sends submitted credentials to next.php, although researchers also observed variants such as nex.php, n3xt.php, and officers*eur.php.

Kratos phishing attack chain targeting US and EU companies (Source: any.run)
Kratos phishing attack chain targeting US and EU companies (Source: any.run)

The newer V2 generation uses obfuscated JavaScript and submits stolen credentials to save.php, ANY.RUN said. In V1, the page function submitData() sends values including di and pr to the collection endpoint.

Victims receive only three password attempts before the site redirects them to a legitimate-looking destination, such as office.com, or displays an incorrect-password error.

This behavior helps attackers distinguish real submissions from random test data. Some sessions also created WebSocket connections.

Researchers cautioned that this can be a risk signal for possible adversary-in-the-middle activity or credential relaying. However, it does not independently prove session-cookie theft.

Indicators of Compromise

IOC typeIndicatorKratos generation / contextDetection use
Asset fingerprint/assets/img/barr.svg + /assets/img/lg.svgV1High-confidence Kratos fingerprint; hunt when both occur in the same browser session
Asset fingerprintdsa.svg + sid.gif + imag.jpgV2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories