Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.
AI Analysis
Technical Summary
Kratos is a mature phishing-as-a-service platform that facilitates credential theft from Microsoft 365 users by deploying convincing phishing pages with anti-bot verification. The operation supports multiple phishing domain deployments, configurable delivery via Telegram or email, and geographic targeting. Researchers identified three generations of the phishing kit (V0, V1, V2) with distinct exfiltration methods and traced 1,484 unique phishing events. The campaign has been active since January 2026, with the operator panel active since September 2025, targeting organizations across more than 20 countries, with a concentration in the US, Spain, and Southern Europe.
Potential Impact
Successful exploitation results in credential theft leading to Microsoft 365 account takeover, which can enable unauthorized access to sensitive organizational data and services. The phishing platform's sophistication, including anti-bot measures and geographic targeting, increases the likelihood of successful credential compromise in targeted regions.
Mitigation Recommendations
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Organizations should implement phishing awareness training, enforce multi-factor authentication (MFA) on Microsoft 365 accounts, and monitor for suspicious login activity. Since the threat targets Microsoft 365 credentials, enabling conditional access policies and using Microsoft Defender for Office 365 anti-phishing features are recommended. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Affected Countries
United States, Spain
Indicators of Compromise
- domain: buenne.de
- domain: enerdizerandtron.de
- domain: ihrsupportcenter.de
- domain: rundwasser.de
- domain: sonnenbrillenspot.de
- domain: dwbud.vilaribit.com
- domain: abal.my
- domain: starwellmedia.com
- domain: aabiz.de
- domain: aspireglobal.ltd
- domain: dufllot.sbs
- domain: espaciocf.de
- domain: ilersls.org
- domain: aaalen.de
- domain: smartcontrolengineer.com
- domain: trisrnareprjdocz.com
- domain: razen.online
- domain: theoceanac.online
- domain: jumpast.es
- ip: 41.128.0.142
- domain: crm-technik.de
- domain: klenpare.com
- domain: uvarnix.cfd
- domain: xavon.sbs
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk
Description
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kratos is a mature phishing-as-a-service platform that facilitates credential theft from Microsoft 365 users by deploying convincing phishing pages with anti-bot verification. The operation supports multiple phishing domain deployments, configurable delivery via Telegram or email, and geographic targeting. Researchers identified three generations of the phishing kit (V0, V1, V2) with distinct exfiltration methods and traced 1,484 unique phishing events. The campaign has been active since January 2026, with the operator panel active since September 2025, targeting organizations across more than 20 countries, with a concentration in the US, Spain, and Southern Europe.
Potential Impact
Successful exploitation results in credential theft leading to Microsoft 365 account takeover, which can enable unauthorized access to sensitive organizational data and services. The phishing platform's sophistication, including anti-bot measures and geographic targeting, increases the likelihood of successful credential compromise in targeted regions.
Defensive Guidance
No official patch or fix applies as this is a phishing campaign rather than a software vulnerability. Organizations should implement phishing awareness training, enforce multi-factor authentication (MFA) on Microsoft 365 accounts, and monitor for suspicious login activity. Since the threat targets Microsoft 365 credentials, enabling conditional access policies and using Microsoft Defender for Office 365 anti-phishing features are recommended. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/"]
- Adversary
- null
- Pulse Id
- 6a566597c655f8331b4e00ad
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainbuenne.de | — | |
domainenerdizerandtron.de | — | |
domainihrsupportcenter.de | — | |
domainrundwasser.de | — | |
domainsonnenbrillenspot.de | — | |
domaindwbud.vilaribit.com | — | |
domainabal.my | — | |
domainstarwellmedia.com | — | |
domainaabiz.de | — | |
domainaspireglobal.ltd | — | |
domaindufllot.sbs | — | |
domainespaciocf.de | — | |
domainilersls.org | — | |
domainaaalen.de | — | |
domainsmartcontrolengineer.com | — | |
domaintrisrnareprjdocz.com | — | |
domainrazen.online | — | |
domaintheoceanac.online | — | |
domainjumpast.es | — | |
domaincrm-technik.de | — | |
domainklenpare.com | — | |
domainuvarnix.cfd | — | |
domainxavon.sbs | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip41.128.0.142 | — |
Threat ID: 6a58afc168715ace43cee4aa
Added to database: 07/16/2026, 10:17:37 UTC
Last enriched: 08/14/2026, 12:41:56 UTC
Last updated: 08/30/2026, 05:01:20 UTC
Views: 179
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.