Kratos Phishing-as-a-Service Infrastructure Dismantled in Major International Law Enforcement Operation

German and US law enforcement agencies, in a coordinated effort with Indonesian authorities, have successfully dismantled the core infrastructure of "Kratos," a sophisticated and widely utilized criminal phishing kit. This operation, described as a significant blow to the cybercrime landscape, has led to the apprehension of the alleged developer and operator of the service. Investigators estimate that Kratos has been responsible for approximately 15,000 phishing campaigns per month, impacting hundreds of thousands of victims across more than 30 countries since late 2024.
The Scope and Sophistication of Kratos
The Kratos phishing kit was not merely designed to steal user credentials; it was engineered to exfiltrate session cookies as well. This critical feature allowed malicious actors to bypass multi-factor authentication (MFA) mechanisms, a security layer intended to protect user accounts. By capturing a valid session cookie, attackers could impersonate legitimate users and gain unauthorized access to their accounts, effectively circumventing what is often considered a robust defense.
Researchers at ANY.RUN, who conducted an in-depth reverse-engineering analysis of the Kratos kit, revealed its dual operational modes. One mode offered a straightforward PHP page focused solely on harvesting login credentials. The second, more advanced mode, employed a Node.js reverse proxy. This sophisticated technique relayed user login attempts to the target service in real-time, simultaneously capturing the resulting session cookie. This adversary-in-the-middle (AiTM) approach significantly undermined the effectiveness of standard MFA implementations, presenting a formidable challenge to cybersecurity defenses.

A Franchise Model for Cybercrime
The operational structure of Kratos mirrored a franchise model, with its paying customers referred to by German investigators as "franchisees." These actors paid for access to the phishing kit using cryptocurrency, managing their accounts and launching campaigns through a dedicated website and a Telegram shop. This streamlined approach lowered the barrier to entry for cybercriminals, enabling even individuals with limited technical expertise to conduct large-scale phishing operations.
Authorities estimate that the operators of Kratos generated over 300,000 euros since the beginning of 2024. The sheer volume of campaigns suggests a substantial financial motivation behind the operation. Each campaign could potentially target several thousand recipients, leading to a widespread impact on individuals and organizations globally.
Chronology of the Operation and Previous Intelligence
The takedown of Kratos was the culmination of extensive investigative work by multiple law enforcement agencies. While the exact timeline of the Kratos operation is not fully detailed, previous intelligence had already flagged its activities. Microsoft Threat Intelligence, for instance, had identified the same kit under the moniker "SneakyLog." Microsoft’s analysis indicated that this phishing-as-a-service platform had been actively engaged in credential and two-factor authentication theft targeting Microsoft 365 users since at least early 2025. Microsoft had previously documented campaigns utilizing this kit, including a notable incident around the 2026 tax season where malicious actors sent tax-themed emails to approximately 100 organizations across various sectors in the United States. These emails contained personalized QR codes leading to fake Microsoft 365 login pages, highlighting the kit’s targeted and sophisticated attack vectors.
The recent joint announcement from the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA) confirmed the successful disruption of Kratos’s core infrastructure. Over 200 servers were taken offline, effectively halting the immediate operational capacity of the phishing kit.

The Broader Implications of the Takedown
The Kratos operation underscores a significant shift in the cybercrime landscape, moving towards highly sophisticated, easily accessible phishing-as-a-service platforms. The ability of Kratos to facilitate AiTM attacks represents a concerning evolution in phishing techniques, directly targeting the perceived security of MFA.
Stolen Credentials: A Gateway to Further Attacks
The implications of Kratos’s success extend far beyond the initial credential theft. The BKA highlighted that stolen Microsoft 365 logins could serve as a springboard for further malicious activities. These could include:
- Subsequent Phishing Attacks: Exploiting the compromised accounts to launch more targeted phishing campaigns against the victim’s contacts or within their organization.
- Sale on the Dark Web: The harvested credentials and session cookies could be sold to other criminal actors, facilitating further exploitation.
- Network Footholds: Gaining access to an organization’s Microsoft 365 environment, which could then be leveraged to spread laterally, potentially leading to Business Email Compromise (BEC) attacks or broader network intrusions.
International Cooperation and Disruptive Tactics
Carsten Meywirth, head of the BKA’s cybercrime division, emphasized the operation’s success in demonstrating that "even highly professional phishing infrastructures can be effectively combated." This sentiment was echoed by Benjamin Krause of the ZIT, who framed the operation as a validation of their "disruptive" strategy. Instead of solely focusing on prosecuting individuals, the ZIT aims to dismantle criminal services at their source, thereby preventing future harm. This proactive approach, involving international collaboration, is crucial in tackling the borderless nature of cybercrime.
Response and Mitigation Strategies
Microsoft has confirmed that it is in the process of notifying users who were impacted by the Kratos-facilitated campaigns. The recommended remediation steps vary depending on the specific method of compromise:

- Credential Harvesting Only: For victims whose credentials were only harvested, a standard password reset, coupled with a re-authentication of MFA, is typically sufficient.
- Session Cookie Exfiltration (AiTM): In cases where the reverse proxy mode was used to capture live session cookies, a simple password reset is insufficient as the active session may persist. In such scenarios, it is imperative to revoke the compromised session and, for high-value accounts, migrate to phishing-resistant sign-in methods.
Technical Indicators for Defenders
Security defenders hunting for signs of Kratos activity can look for specific technical indicators. ANY.RUN’s analysis revealed that Kratos login pages frequently load two specific image assets: barr.svg and lg.svg. These pages then typically POST stolen credentials to endpoints such as next.php or save.php. The consistent pairing of these elements has been identified as a strong indicator, boasting a high recall rate with minimal false positives, making it a valuable tool for threat hunting.
The Lingering Threat and Future Outlook
While the takedown of Kratos’s core infrastructure represents a significant victory for law enforcement, the threat is not entirely eradicated. The roughly 1,800 identified customers, or "franchisees," who already possess the kit code, remain a concern. Furthermore, the nature of Kratos’s deployment – utilizing disposable domains, compromised WordPress sites, and shared hosting with other AiTM kits – suggests that the underlying technology and operational model are adaptable. It is highly probable that the Kratos operation will resurface under a new name or guise, underscoring the persistent cat-and-mouse game between cybercriminals and law enforcement.
This operation highlights the critical need for continued international cooperation, advanced threat intelligence sharing, and the development of more robust and resilient authentication mechanisms. As cybercriminals evolve their tactics, so too must the strategies and tools employed by defenders to safeguard individuals and organizations in the increasingly digital world. The dismantling of Kratos serves as a powerful reminder of the ongoing battle against sophisticated cyber threats and the importance of proactive, collaborative cybersecurity efforts.







