- German and US law enforcement shut down more than 200 servers powering the Kratos phishing kit, arresting its alleged developer in Indonesia.
- Kratos used an adversary-in-the-middle technique to steal session cookies, bypassing two-factor authentication for Microsoft 365 accounts.
- Since late 2024, the kit targeted hundreds of thousands of victims across 30+ countries, with operators earning over $327,000 in cryptocurrency.
German and US law enforcement dismantled the core infrastructure of Kratos, a phishing-as-a-service platform they describe as one of the world’s most widely used criminal kits, while Indonesian authorities arrested the man believed to have developed and operated it. The Frankfurt prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA) announced Monday that they had pulled more than 200 servers offline, estimating roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns monthly.
The kit harvested more than just passwords, according to the BKA, as it was designed to steal session cookies along with logins—a technique that allows attackers to bypass two-factor authentication. ANY.RUN, which reverse-engineered the kit, found operators could choose between a plain PHP page harvesting credentials or a Node.js reverse proxy that relayed Microsoft 365 logins in real time to capture the resulting session.
Authorities described the operation as a franchise model, where customers paid in cryptocurrency via a dedicated website and Telegram shop. The BKA estimates that operators have earned more than $327,000 since 2024, with each campaign hitting several thousand recipients.
Microsoft Threat Intelligence tracks the same kit as SneakyLog, a platform it says has targeted Microsoft 365 since at least early 2025. One campaign on February 10 sent tax-themed emails with personalized QR codes leading to fake Microsoft 365 login pages to about 100 US organizations.
The stolen credentials can be used for further phishing, sold to other criminals, or used to compromise businesses through their Microsoft 365 environments. Carsten Meywirth, head of the BKA’s cybercrime division, said the operation shows “that even highly professional phishing infrastructures can be effectively combated.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- Solana Price Prediction: Surge to $83 by August 1?
- Balance Coin stablecoin falls 99% after oracle manipulation
- CFTC short-staffed for prediction market oversight, hearing told
- Apple fixes Hide My Email flaw that leaked real addresses for over a year
- White House pushes Dems to accept Trump’s crypto ethics deal
