Cybersecurity & Protection

German and US Law Enforcement Dismantle Global Phishing-as-a-Service Operation "Kratos," Indonesian Authorities Arrest Alleged Developer

German and US law enforcement agencies, in a coordinated international effort, have successfully dismantled the core infrastructure of "Kratos," a sophisticated phishing-as-a-service (PhaaS) operation described as one of the most widely utilized criminal tools globally. The operation, characterized by its advanced capabilities in bypassing multi-factor authentication (MFA), saw the takedown of over 200 servers. Concurrently, Indonesian authorities have apprehended a key suspect believed to be the mastermind behind the development and operation of Kratos.

The joint announcement, made on Monday by the Frankfurt Public Prosecutor’s Cybercrime Unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), detailed the significant blow dealt to this extensive criminal enterprise. Investigators estimate that approximately 1,800 paying customers, referred to as "franchisees" by the BKA, utilized Kratos to orchestrate an estimated 15,000 phishing campaigns each month. This widespread adoption highlights the accessibility and effectiveness of the service for cybercriminals of varying technical proficiencies.

The Advanced Threat of Kratos: Beyond Simple Credential Harvesting

Kratos distinguished itself from more rudimentary phishing tools by its ability to do more than just harvest usernames and passwords. The kit was meticulously designed to also capture session cookies, a crucial element for maintaining authenticated access to online accounts. The BKA highlighted that this captured session cookie, when combined with stolen credentials, provided attackers with a direct pathway to bypass even multi-factor authentication (MFA) mechanisms, effectively impersonating legitimate users.

Further analysis by ANY.RUN, a cybersecurity firm that reverse-engineered the Kratos kit, revealed the sophisticated methods employed. Operators had the option of deploying two distinct modes: a basic PHP page designed solely for credential collection, or a more advanced Node.js reverse proxy. This latter mode acted as an adversary-in-the-middle (AiTM) tool. It would relay login requests to legitimate services, such as Microsoft, in real-time, thereby capturing the authentication session as it was established. This AiTM technique proved particularly effective in circumventing traditional MFA implementations, rendering them significantly less robust than anticipated by many users and organizations.

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

A Franchise Model for Cybercrime

The operational structure of Kratos mirrored a franchise model, allowing individuals with limited technical expertise to engage in large-scale phishing attacks. Customers subscribed to the service through a dedicated website and a Telegram shop, which facilitated account management and campaign organization. Payment for the service was exclusively conducted in cryptocurrency, a common practice among cybercriminals to obscure financial transactions.

This accessibility democratized cybercrime, enabling a broad spectrum of actors to launch sophisticated attacks. The estimated earnings of the Kratos operators since late 2024 have exceeded 300,000 euros, with each individual campaign potentially impacting several thousand recipients. The geographical reach of these attacks has been extensive, with hundreds of thousands of victims identified across more than 30 countries, predominantly in Europe and the United States, since late 2024.

International Collaboration and the Kratos Takedown

The successful takedown was the result of a collaborative effort involving German law enforcement agencies, including the ZIT and BKA, and their counterparts in the United States. The investigation culminated in the seizure of critical infrastructure, effectively disrupting the operational capabilities of Kratos. The arrest in Indonesia of an individual believed to be the developer and operator marks a significant achievement in holding individuals accountable for facilitating widespread cybercrime.

Carsten Meywirth, head of the BKA’s cybercrime division, expressed confidence in the operation’s success, stating that it demonstrates "that even highly professional phishing infrastructures can be effectively combated." Benjamin Krause of the ZIT further emphasized the unit’s proactive "disruptive" approach, which aims to dismantle criminal services in their entirety rather than solely focusing on prosecuting individual perpetrators.

Chronology of the Kratos Operation and its Recognition

The threat posed by Kratos was not entirely unknown to cybersecurity researchers and threat intelligence firms. Microsoft Threat Intelligence had previously identified the same kit under the moniker "SneakyLog." This platform was recognized as a phishing-as-a-service that had been actively engaged in credential and two-factor authentication theft targeting Microsoft 365 environments since at least early 2025. Microsoft had even documented instances of its detection, including a specific campaign observed in March 2026, which leveraged tax-season-related lures.

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

A notable campaign, detailed by the BKA and consistent with Microsoft’s findings, occurred on February 10th of this year. Operators disseminated tax-themed emails to approximately 100 organizations across various sectors, including manufacturing, retail, and healthcare, with a primary focus on the United States. These emails contained a personalized W-2 document with a QR code. Upon scanning, the QR code directed recipients to a counterfeit Microsoft 365 login page, designed to steal their credentials and session cookies.

The Broader Implications of Session Cookie Theft

The ability of Kratos to steal session cookies represents a significant escalation in phishing tactics. Once a user successfully logs in, their browser typically receives a session cookie that keeps them authenticated for a period, eliminating the need to re-enter credentials for subsequent interactions with the service. By stealing this cookie, attackers could effectively bypass MFA checks, as the compromised session appeared legitimate to the targeted service. This "session hijacking" allows attackers to impersonate the victim, access their accounts, and potentially perform malicious actions without ever needing to circumvent the MFA prompt itself.

The stolen credentials and session cookies from Kratos were not merely an endpoint for attackers. The BKA indicated that this compromised information could be leveraged for further phishing attacks, sold on the dark web to other criminal actors, or used as an initial foothold for broader network intrusion. The familiar pathway from a single phished inbox to significant business email compromise (BEC) attacks underscores the pervasive threat posed by such sophisticated phishing operations.

Microsoft’s Response and User Protection Measures

Microsoft has been actively involved in notifying users who may have been affected by Kratos-powered phishing campaigns. The remediation process depends on the specific method of compromise. For instances where only credentials were harvested, a standard password reset and a new MFA verification would typically suffice. However, in cases where the AiTM reverse proxy captured a live session cookie, simply resetting the password would not invalidate the existing compromised session. In such scenarios, explicit revocation of the active session is required. Microsoft also advises high-value accounts to transition to phishing-resistant sign-in methods, such as FIDO2 security keys or Windows Hello for Business, to bolster their security posture.

Identifying the Traces of Kratos

Cybersecurity defenders have been provided with indicators of compromise to aid in the detection of Kratos-related activity. ANY.RUN’s analysis revealed that Kratos login pages consistently load two specific image assets: "barr.svg" and "lg.svg." Furthermore, stolen credentials were often POSTed to backend endpoints named "next.php" or "save.php." The firm asserts that this pairing of assets and endpoints offers a high degree of accuracy in identifying Kratos phishing attempts, with a recall rate of approximately 90% and minimal false positives.

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

The Future of Phishing-as-a-Service

While the takedown of Kratos’s core infrastructure is a significant victory, the cybersecurity landscape remains dynamic. The BKA acknowledges that the approximately 1,800 customers who previously utilized the service and the underlying kit code they possess are not directly impacted by this operation. ANY.RUN’s observations of Kratos operating on disposable domains, compromised WordPress sites, and shared hosting environments with other AiTM kits suggest a resilient ecosystem. This indicates that once a particular infrastructure is dismantled, similar operations are likely to re-emerge under new names and with updated techniques. The ongoing cat-and-mouse game between law enforcement and cybercriminals necessitates continuous vigilance, adaptation, and international cooperation. The Kratos takedown serves as a potent reminder of the evolving sophistication of cyber threats and the critical importance of robust cybersecurity defenses for individuals and organizations alike.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Lock It Soft
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.