Trust-Path Phishing: Kratos Turns Microsoft 365 Sharing Into a Credential Trap
A subscription phishing kit is using familiar cloud-sharing patterns and bot checks to steer Microsoft 365 users toward fake sign-in pages.
The campaign behind Kratos shows how little malware is needed when attackers can borrow the look and timing of normal work. Instead of dropping files or noisy payloads, the operation leans on trusted collaboration services and redirects that resemble everyday document sharing. The result is a phishing flow that can feel routine long enough to push a user into entering credentials.
Fast Facts
- Kratos is described as a subscription-based phishing-as-a-service platform.
- The campaign targets Microsoft 365 users in the United States, Europe, and other regions.
- Trusted services such as SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io are part of the delivery chain.
- The links ultimately route victims toward credential-harvesting pages.
- Cloudflare anti-bot checks are used to make analysis and inspection harder.
Why this kind of phishing works
The technical trick is not exotic. It is trust laundering. Microsoft 365 collaboration tools are built for external sharing, guest access, and cross-organization work, so a link that looks like a file invitation does not immediately stand out as malicious. When that link is wrapped in redirects through branded cloud services, the user may see several familiar names before ever reaching the real payload.
That matters because phishing defenses are often tuned to catch obvious lookalike login pages, not chains that begin with what appears to be a shared document. In this model, the attacker is not trying to win on code quality. The attacker is trying to win on workflow familiarity.
Cloudflare anti-bot checks add another layer of friction. From a defensive perspective, those checks can slow down crawlers, sandboxes, and rapid triage, which gives the phishing infrastructure more time to stay alive. They do not prove a specific Cloudflare product was used, but they do fit a common pattern in modern phishing kits: delay inspection, separate humans from automation, and push the real lure deeper into the chain.
For Microsoft 365 tenants, the risk is not just a stolen password. A captured account can become a foothold for mailbox abuse, internal phishing, and access to shared files or connected services, depending on the tenant’s controls and the victim’s permissions. That is why identity protection and sharing policy review matter as much as URL filtering.
At the time of writing, the available information supports a risk analysis, not a claim of broader compromise or a precise count of affected sessions.
Defensive lessons
Security teams should treat document-sharing prompts that lead into sign-in flows as high-friction events, especially when multiple redirects or challenge pages appear first. In Microsoft environments, the practical controls are familiar: tighten SharePoint and OneDrive external-sharing scope, review Microsoft Entra B2B guest settings, and use Microsoft Defender for Office 365 anti-phishing policies to improve impersonation detection and quarantine suspicious messages.
The broader lesson is simple: modern phishing often succeeds by looking operational, not alarming. When attackers can borrow the credibility of collaboration tools, the defense has to focus on trust boundaries, not just malicious attachments.
Conclusion
Kratos is a reminder that cybercrime increasingly thrives inside normal business behavior. The danger is not only the fake login page at the end, but the chain of trusted services that makes the page feel earned. In cloud-first environments, every shared link deserves the same scrutiny as an unknown attachment.
TECHCROOK
hardware security key: A hardware security key adds a phishing-resistant layer to Microsoft 365 and other accounts. It works best alongside strong passwords and careful review of external sharing prompts. Choose a USB-C, USB-A, or NFC model that matches your devices and account setup.
WIKICROOK
- Phishing-as-a-Service (PhaaS): A subscription model where phishing tools, templates, and infrastructure are rented to operators.
- Credential Harvesting: A fake login process designed to capture usernames and passwords.
- External Sharing: A cloud feature that lets users share files or folders with people outside their organization.
- Bot Check: A challenge or scoring step used to separate human visitors from automated traffic.
- Microsoft Entra B2B: Microsoft’s external collaboration model for managing guest access across organizations.



