Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

​​Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk​

0
Medium
Published: 07/14/2026 (07/14/2026, 16:36:39 UTC)
Source: AlienVault OTX General

Description

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:41:56 UTC

Technical Analysis

Kratos is a mature phishing-as-a-service platform that facilitates credential theft from Microsoft 365 users by deploying convincing phishing pages with anti-bot verification. The operation supports multiple phishing domain deployments, configurable delivery via Telegram or email, and geographic targeting. Researchers identified three generations of the phishing kit (V0, V1, V2) with distinct exfiltration methods and traced 1,484 unique phishing events. The campaign has been active since January 2026, with the operator panel active since September 2025, targeting organizations across more than 20 countries, with a concentration in the US, Spain, and Southern Europe.

Potential Impact

Successful exploitation results in credential theft leading to Microsoft 365 account takeover, which can enable unauthorized access to sensitive organizational data and services. The phishing platform's sophistication, including anti-bot measures and geographic targeting, increases the likelihood of successful credential compromise in targeted regions.

Defensive Guidance

No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Organizations should implement phishing awareness training, enforce multi-factor authentication (MFA) on Microsoft 365 accounts, and monitor for suspicious login activity. Since the threat targets Microsoft 365 credentials, enabling conditional access policies and using Microsoft Defender for Office 365 anti-phishing features are recommended. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/"]
Adversary
null
Pulse Id
6a566597c655f8331b4e00ad
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainbuenne.de
domainenerdizerandtron.de
domainihrsupportcenter.de
domainrundwasser.de
domainsonnenbrillenspot.de
domaindwbud.vilaribit.com
domainabal.my
domainstarwellmedia.com
domainaabiz.de
domainaspireglobal.ltd
domaindufllot.sbs
domainespaciocf.de
domainilersls.org
domainaaalen.de
domainsmartcontrolengineer.com
domaintrisrnareprjdocz.com
domainrazen.online
domaintheoceanac.online
domainjumpast.es
domaincrm-technik.de
domainklenpare.com
domainuvarnix.cfd
domainxavon.sbs

Ip

ValueDescriptionCopy
ip41.128.0.142

Threat ID: 6a58afc168715ace43cee4aa

Added to database: 07/16/2026, 10:17:37 UTC

Last enriched: 08/14/2026, 12:41:56 UTC

Last updated: 08/30/2026, 05:01:20 UTC

Views: 179

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses