HackMyIP
← Back to News
2026-07-22 The Hacker News

Kratos Phishing Kit Takedown: 200+ Servers Offline, Developer Arrested

PhishingAuthenticationIncident Response

German and US law enforcement have dismantled the core infrastructure of Kratos, a phishing-as-a-service kit investigators describe as one of the most widely used criminal phishing platforms in the world. In a joint announcement, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline, while Indonesian authorities arrested the suspected developer and operator. Investigators estimate roughly 1,800 paying customers used Kratos to run approximately 15,000 phishing campaigns per month, targeting victims across more than 30 countries and earning operators over 300,000 euros since 2024.

Kratos stood out for its ability to bypass multi-factor authentication. Operators could deploy the kit in two modes: a basic PHP page that harvests credentials, or a Node.js reverse proxy that relays the Microsoft 365 login in real time, capturing the resulting session cookie. As the BKA noted, stealing the session cookie is enough to walk past two-factor authentication directly into the victim's account. The platform ran like a franchise, with customers paying in cryptocurrency and managing campaigns through a dedicated website and Telegram shop, allowing even low-skill actors to launch adversary-in-the-middle (AiTM) attacks against Microsoft 365 users. Microsoft Threat Intelligence tracks the same kit as SneakyLog, documenting a February 2025 campaign that sent tax-themed W-2 lures with personalized QR codes to roughly 100 organizations across manufacturing, retail, and healthcare.

The takedown highlights how stolen Microsoft 365 credentials rarely end at the inbox. The BKA warned that harvested sessions could fuel further phishing, be sold to other criminals, or pivot into business email compromise by spreading through connected cloud environments. BKA cybercrime chief Carsten Meywirth said the operation proves "that even highly professional phishing infrastructures can be effectively combated," while ZIT's Benjamin Krause framed it as validation of a disruptive approach focused on dismantling criminal services outright. With credentials from hundreds of thousands of victims now potentially exposed, users should verify whether their accounts appear in known incidents using an email breach checker, rotate any reused passwords after testing them against a password checker, and review their overall exposure with a privacy checkup to confirm no active sessions or unauthorized device links remain on their Microsoft 365 accounts.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →