More than 200 servers were pulled offline, and investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month.
The disruption: ZIT and the BKA take down core infrastructure, Indonesian arrest
German and US law enforcement, coordinated by the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA), announced a joint action that removed more than 200 servers tied to Kratos. Indonesian authorities arrested the individual they say developed and operated the kit. Authorities described the move as a disruption of Kratos's central infrastructure; the BKA said Kratos-powered campaigns cannot continue while those servers remain offline.
How Kratos worked: credential harvesting, session-cookie theft, and AiTM proxy
Investigators and analysts described Kratos as a phishing kit built to do more than steal passwords. The BKA said the kit was designed to harvest the session cookie along with the login — and that cookie alone is enough to "walk past two-factor authentication into the account as the user." Reverse engineering by ANY.RUN found two operational modes. One was a plain PHP page that only harvested credentials. The other was a Node.js reverse proxy that relayed logins to Microsoft in real time and captured the resulting session — an adversary-in-the-middle (AiTM) technique that can defeat ordinary multi-factor authentication.
Scale and commerce: franchise model, customers, victims, and earnings
Authorities described Kratos as a franchise-style phishing-as-a-service. Customers — called franchisees by the BKA — paid in cryptocurrency and signed up through a dedicated website and a Telegram shop to manage accounts and campaigns, enabling lower-skill operators to launch sophisticated AiTM attacks. Investigators estimate roughly 1,800 paying customers ran about 15,000 phishing campaigns each month; victims since late 2024 number in the hundreds of thousands across more than 30 countries, concentrated in Europe and the United States. The BKA estimated operators earned more than 300,000 euros since 2024, and said individual campaigns could target several thousand recipients.
Microsoft's tracking and a concrete campaign caught in the act
Microsoft Threat Intelligence identifies the same kit as "SneakyLog" and said the platform has been used against Microsoft 365 since at least early 2025. Microsoft reported catching one campaign in the act on February 10: operators sent tax-themed emails to about 100 organizations, mostly in the United States and spanning manufacturing, retail, and healthcare; each message carried a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login.
The BKA warned that stolen Microsoft logins are rarely the final objective: credentials and sessions can be repurposed for further phishing, sold to other criminals, or used to gain a foothold inside companies and move laterally through Microsoft 365 environments — the pathway that frequently leads to business email compromise.
How Microsoft, enterprise security teams, and end users are responding
- Microsoft: Microsoft is notifying users caught in Kratos campaigns. The company distinguishes between credential-only theft and live-session theft; credential-only incidents are addressed with a password reset and an MFA check, while live-session theft requires session revocation and moving high-value accounts to phishing-resistant sign-in.
- Enterprise security teams: Defenders are being pointed to concrete indicators. ANY.RUN found Kratos login pages almost always load paired assets barr.svg and lg.svg and then POST credentials to endpoints such as next.php or save.php — a pairing the researcher rates at 90% recall with near-zero false positives. Those artifacts and POST endpoints give defenders practical detection handles.
- End users: Where Kratos operated as a reverse proxy, simple credential resets are insufficient because captured sessions can survive a password change; affected accounts must have sessions revoked and be migrated to phishing-resistant authentication for high-risk users.
What the takedown did — and did not — accomplish
The operation removed Kratos's central servers and, according to the BKA, stopped ongoing Kratos-powered campaigns for the moment. But the takedown did not confiscate the kit code in the hands of roughly 1,800 customers, nor did it remove the disposable infrastructure analysts found in use: Kratos instances ran on disposable domains, compromised WordPress sites, and hosting environments shared with other AiTM kits. ANY.RUN warned that such setups are the kind that can reappear under a new name once core servers are taken down.
Carsten Meywirth, head of the BKA's cybercrime division, framed the action as proof that "even highly professional phishing infrastructures can be effectively combated." Benjamin Krause of the ZIT described the move as evidence of the office's "disruptive" approach of dismantling a criminal service outright rather than only charging the people behind it. The facts at hand show a disruption with immediate effect — but also the structural fragility of a takedown that does not touch the distributed customers and disposable hosting that enable rapid reconstitution.
Original story: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html



