Kratos PhaaS activity is rising across Europe, with more than 100 related analysis sessions recorded in ANY.RUN’s Interactive Sandbox over the past week. The growth appears to be driven by an updated phishing flow designed to increase conversion while reducing obvious triage signals.
The latest version replaces the static /SOft landing URI and weak secure-document lure with common-looking URIs, a more convincing Microsoft credential-harvesting flow, and a final redirect to the legitimate office[.]com domain.
These changes can delay user reporting, complicate triage, and increase the risk of missed credential theft across manufacturing, technology, and MSSP organizations.
How the Kratos Phishing Flow Has Changed
Earlier Kratos samples were easier to recognize during triage. They commonly used the same /SOft landing URI and a basic “Secure Document Access” lure that looked less convincing and provided analysts with a repeatable indicator.

The updated version removes these obvious patterns. It uses common-looking URIs and a Microsoft-style authentication page that more closely resembles a legitimate login flow. See the full updated Kratos attack flow and collect IOCs.
How the updated attack works:
- The victim opens the phishing page: The page displays a Microsoft credential form hosted under a URI that could easily be mistaken for a normal website path.
- The victim enters an email and password: The submitted data is sent through a POST request to /next.php. The di parameter contains the email address, while pr carries the password.
- The page shows an “Incorrect Password” message: Instead of ending the interaction, the page asks the victim to try again. This makes the flow appear more realistic and may give the attacker a second password.
- The victim is redirected to the legitimate office[.]com website: After the second submission, the phishing page sends the user to the real Microsoft website. The incident may therefore look like a simple failed login rather than successful credential theft.
This complete sequence can be confirmed through the browser-level visibility available inside ANY.RUN Sandbox. In the Browser Data tab, analysts can inspect the credential submission request, verify the di and pr parameters, and follow the redirect that occurs after the credentials are captured.

By reproducing the interaction rather than reviewing only the landing page, analysts can confirm credential exfiltration, understand the full redirect chain, and collect stronger evidence for detection and response.
Confirm phishing behavior sooner, reduce investigation and handoff time, and contain credential theft before it increases SOC costs or disrupts the business. Speed Up Phishing Response.
Track Related Kratos Activity Across Europe and the US
A single analysis confirms how the phishing page behaves, but it does not reveal the full scale or geographic reach of the campaign. Analysts can use ANY.RUN’s Threat Intelligence Lookup to pivot from observed indicators and uncover other sessions linked to Kratos activity across Europe, the US, and other regions.

The available query helps teams identify related domains, recurring infrastructure, reused phishing components, and changes in landing URIs. This allows analysts to track how the campaign develops, compare activity across regions, and find indicators that may already appear in internal telemetry.
Detection Opportunities for SOC Teams
The updated Kratos flow shows why detection should not rely on the /SOft URI or the appearance of the landing page alone. Analysts should combine browser behavior, network requests, redirect activity, and campaign infrastructure when building detection logic.
Useful signals include:
- Microsoft login pages hosted outside legitimate Microsoft infrastructure
- POST requests to /next.php after form submission
- Requests containing the di and pr parameters
- An “Incorrect Password” message after the first credential submission
- A second form submission from the same browser session
- A redirect to office[.]com after credential capture
- Domains and infrastructure connected to other Kratos sessions
Because endpoints such as /next.php can also appear on legitimate websites, these indicators should be correlated rather than used independently.
Turn Faster Phishing Detection into Lower Business Risk
When credential theft is hidden behind a realistic login flow, every delay adds cost. Analysts spend longer validating the page, escalated cases require repeated investigation, and containment may begin only after the compromised account is used.
A faster investigation process can help organizations achieve:
- Accelerate phishing triage and threat hunting
- Reduce analyst time spent on each case
- Lower investigation and escalation costs
- Speed up Tier 1-to-Tier 2 handoffs
- Contain affected accounts and infrastructure sooner
- Reduce the risk of fraud, cloud abuse, and disruption
- Avoid higher recovery costs by stopping incidents earlier
By moving from suspicious page to confirmed behavior faster, security teams can reduce both the operational burden on the SOC and the financial impact of phishing incidents.
Strengthen phishing defense with faster behavioral analysis, clearer handoffs, and earlier containment that lowers both SOC costs and business risk.