Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Law Enforcement Shuts Down Major Kratos Phishing Network

Law Enforcement Shuts Down Major Kratos Phishing Network

Posted on July 22, 2026 By CWS

German and US law enforcement agencies have successfully dismantled the core infrastructure of the Kratos phishing network, a notorious platform utilized globally for cybercriminal activities. In a coordinated effort, Indonesian officials arrested the individual believed to be the mastermind behind this operation.

International Cooperation in Cybersecurity

In a joint statement on Monday, the cybercrime division of the Frankfurt public prosecutor’s office and Germany’s Federal Criminal Police Office (BKA) announced the takedown of over 200 servers linked to Kratos. Authorities disclosed that approximately 1,800 users had employed Kratos to conduct an estimated 15,000 phishing campaigns each month.

Kratos was not limited to stealing passwords. It had the capability to capture session cookies, allowing attackers to bypass multi-factor authentication (MFA) and gain access to accounts under the guise of legitimate users, according to the BKA.

Technical Insights into Kratos Operations

The research team at ANY.RUN reverse-engineered the phishing kit, revealing two operational modes. The first mode involved a simple PHP page for credential harvesting, while the second utilized a Node.js reverse proxy to intercept logins in real-time. This sophisticated adversary-in-the-middle technique significantly undermines the effectiveness of standard MFA protocols.

The Kratos operation functioned like a franchise model, where users paid with cryptocurrency to gain access via a dedicated website and Telegram channels. This structure enabled even those with minimal technical skills to deploy the phishing kit against targets effectively.

Impact and Future Implications

Authorities estimate that since late 2024, Kratos has affected hundreds of thousands of victims across more than 30 countries, primarily in Europe and the United States. The perpetrators reportedly amassed over 300,000 euros from these criminal activities.

Microsoft Threat Intelligence had been tracking Kratos, identifying it as SneakyLog, known for its credential and 2FA theft targeting Microsoft 365 users since early 2025. A notable campaign involved sending tax-related emails to approximately 100 US-based organizations, which included a deceptive Microsoft 365 login page.

While the takedown of Kratos servers has halted its operations temporarily, the underlying threat persists as customers retain the kit code. The BKA warns that similar operations could resurface using alternative means and infrastructure.

Microsoft is actively notifying affected users, advising them on appropriate remedial actions. These include password resets and MFA checks, particularly in cases where session cookies were harvested, necessitating session revocation.

Despite the success of this operation, cybersecurity experts stress the ongoing need for vigilance and the implementation of robust phishing-resistant authentication methods to safeguard against future threats.

The Hacker News Tags:BKA, Cybercrime, Cybersecurity, Germany, Kratos, law enforcement, MFA, Microsoft 365, Phishing, US

Post navigation

Previous Post: GolangGhost Malware Targets Crypto Professionals
Next Post: Coca-Cola’s Fairlife Hit by Anubis Ransomware Attack

Related Posts

Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code The Hacker News
New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands The Hacker News
The Future of Cybersecurity Includes Non-Human Employees The Future of Cybersecurity Includes Non-Human Employees The Hacker News
See Threats to Your Industry & Country in Real Time See Threats to Your Industry & Country in Real Time The Hacker News
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers The Hacker News
Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 204 Zero-Day Exploits Released Before Patches Available
  • Glow Debuts with $180M Funding and $1.2B Valuation
  • Critical ServiceNow Flaw Under Active Exploitation
  • Oracle Enhances Security with Over 1,400 Patches
  • OpenAI AI Models Breach Security, Target Hugging Face

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 204 Zero-Day Exploits Released Before Patches Available
  • Glow Debuts with $180M Funding and $1.2B Valuation
  • Critical ServiceNow Flaw Under Active Exploitation
  • Oracle Enhances Security with Over 1,400 Patches
  • OpenAI AI Models Breach Security, Target Hugging Face

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark