
Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials
The kit combines trusted cloud services, Cloudflare Turnstile challenges, convincing Microsoft login clones, and PHP-based credential collection endpoints to evade detection and steal enterprise credentials. The operation has been active in ANY.RUN sandbox telemetry since January 2026, while its operator panel appears to have existed since at least September 2025. Researchers identified 1,6281{,}6281,628 sandbox sessions […]
The post Kratos Uses Cloudflare Turnstile, Obfuscated Login Pages, and PHP Endpoints to Exfiltrate Credentials appeared first on Cyber Security News.