German and US law enforcement agencies have successfully dismantled the core infrastructure of the Kratos phishing network, a notorious platform utilized globally for cybercriminal activities. In a coordinated effort, Indonesian officials arrested the individual believed to be the mastermind behind this operation.
International Cooperation in Cybersecurity
In a joint statement on Monday, the cybercrime division of the Frankfurt public prosecutor’s office and Germany’s Federal Criminal Police Office (BKA) announced the takedown of over 200 servers linked to Kratos. Authorities disclosed that approximately 1,800 users had employed Kratos to conduct an estimated 15,000 phishing campaigns each month.
Kratos was not limited to stealing passwords. It had the capability to capture session cookies, allowing attackers to bypass multi-factor authentication (MFA) and gain access to accounts under the guise of legitimate users, according to the BKA.
Technical Insights into Kratos Operations
The research team at ANY.RUN reverse-engineered the phishing kit, revealing two operational modes. The first mode involved a simple PHP page for credential harvesting, while the second utilized a Node.js reverse proxy to intercept logins in real-time. This sophisticated adversary-in-the-middle technique significantly undermines the effectiveness of standard MFA protocols.
The Kratos operation functioned like a franchise model, where users paid with cryptocurrency to gain access via a dedicated website and Telegram channels. This structure enabled even those with minimal technical skills to deploy the phishing kit against targets effectively.
Impact and Future Implications
Authorities estimate that since late 2024, Kratos has affected hundreds of thousands of victims across more than 30 countries, primarily in Europe and the United States. The perpetrators reportedly amassed over 300,000 euros from these criminal activities.
Microsoft Threat Intelligence had been tracking Kratos, identifying it as SneakyLog, known for its credential and 2FA theft targeting Microsoft 365 users since early 2025. A notable campaign involved sending tax-related emails to approximately 100 US-based organizations, which included a deceptive Microsoft 365 login page.
While the takedown of Kratos servers has halted its operations temporarily, the underlying threat persists as customers retain the kit code. The BKA warns that similar operations could resurface using alternative means and infrastructure.
Microsoft is actively notifying affected users, advising them on appropriate remedial actions. These include password resets and MFA checks, particularly in cases where session cookies were harvested, necessitating session revocation.
Despite the success of this operation, cybersecurity experts stress the ongoing need for vigilance and the implementation of robust phishing-resistant authentication methods to safeguard against future threats.
