Kratos Phishing-as-a-Service Infrastructure Dismantled in Major International Law Enforcement Operation

In a significant victory for global cybersecurity, a coordinated operation by German and U.S. law enforcement agencies has successfully dismantled the core infrastructure of Kratos, a sophisticated and widely utilized criminal phishing kit. Indonesian authorities have concurrently apprehended the individual alleged to be the mastermind behind its development and operation. This crackdown represents a major blow to cybercriminals who have leveraged Kratos to conduct widespread phishing campaigns, compromising sensitive user credentials and bypassing multi-factor authentication (MFA) safeguards.
The Scope of the Kratos Operation
The Frankfurt Public Prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), in a joint announcement made on Monday, July 22, 2026, revealed the takedown of over 200 servers that formed the backbone of the Kratos operation. Investigators estimate that approximately 1,800 paying customers, referred to by the BKA as "franchisees," utilized Kratos to launch an astonishing 15,000 phishing campaigns per month. This scale underscores the pervasive threat posed by such sophisticated, easily accessible cybercrime tools.
Kratos distinguished itself from more rudimentary phishing kits by its advanced capabilities. Beyond merely harvesting usernames and passwords, the kit was engineered to capture session cookies. This critical element allowed threat actors to bypass two-factor authentication (2FA) and gain direct access to user accounts, effectively impersonating legitimate users.

Advanced Techniques and Phishing-as-a-Service Model
Analysis conducted by ANY.RUN, a cybersecurity firm that reverse-engineered the Kratos kit, shed light on its insidious functionality. Operators had the option of deploying two distinct modes. The first was a straightforward PHP page designed solely for credential harvesting. However, the more alarming mode utilized a Node.js reverse proxy. This advanced feature enabled attackers to relay login requests to target services, such as Microsoft, in real-time, thereby capturing the resulting session cookie. This "adversary-in-the-middle" (AiTM) technique proved highly effective in circumventing conventional MFA, rendering it a less robust defense than commonly perceived.
The Kratos operation was structured as a "phishing-as-a-service" (PhaaS) model, mirroring legitimate business franchises. Customers paid in cryptocurrency, managing their accounts and orchestrating campaigns through a dedicated website and a Telegram shop. This streamlined approach lowered the barrier to entry for aspiring cybercriminals, enabling even individuals with limited technical expertise to execute potent phishing attacks.
Global Reach and Financial Impact
Authorities estimate that since late 2024, Kratos has victimized hundreds of thousands of individuals across more than 30 countries, with a significant concentration of attacks in Europe and the United States. The financial gains for the operators are substantial, with an estimated revenue exceeding 300,000 euros since the beginning of 2024. Each phishing campaign could potentially target several thousand recipients, highlighting the significant potential for widespread damage.
Prior Warnings and Identifications
The Kratos kit was not entirely unknown to the cybersecurity community. Microsoft Threat Intelligence had previously identified the same kit under the moniker "SneakyLog." Microsoft’s analysis, published in March 2026, detailed how SneakyLog was employed as a phishing-as-a-service platform targeting Microsoft 365 accounts for credential and 2FA theft, with operations dating back to at least early 2025. Microsoft had even documented specific campaigns utilizing this kit, including one observed in March 2026 that employed tax-related lures during the peak tax season.

Timeline of Key Events and Discoveries:
- Early 2025: Microsoft Threat Intelligence begins tracking activity associated with the Kratos/SneakyLog phishing kit, noting its focus on Microsoft 365 credential and 2FA theft.
- March 2026: Microsoft publishes research detailing "SneakyLog" and its use in tax-themed phishing campaigns targeting organizations, particularly in the US, across manufacturing, retail, and healthcare sectors. These campaigns featured personalized W-2 documents with QR codes leading to fake Microsoft 365 login pages.
- Late 2024 – July 2026: The Kratos operation, operating as a PhaaS, actively recruits and serves approximately 1,800 paying customers, launching an estimated 15,000 phishing campaigns per month, affecting hundreds of thousands of victims across over 30 countries.
- February 10, 2026: A notable campaign observed by Microsoft targets around 100 organizations with tax-themed lures.
- July 22, 2026: German and U.S. law enforcement agencies, in conjunction with Indonesian authorities, announce the successful takedown of Kratos’s core infrastructure and the arrest of its alleged developer.
The Broader Implications of Stolen Credentials
The ramifications of compromised Microsoft 365 credentials extend far beyond initial account access. The BKA has highlighted that these stolen credentials can be exploited for a multitude of malicious purposes. They can be used to launch further phishing attacks against an organization’s contacts, sold on the dark web to other criminal entities, or serve as an entry point for more sophisticated intrusions. By leveraging the trust inherent in a compromised Microsoft 365 environment, threat actors can facilitate business email compromise (BEC) schemes and other damaging cyberattacks.
Official Reactions and Law Enforcement Strategies
Carsten Meywirth, head of the BKA’s cybercrime division, expressed confidence in the operation’s success, stating that it demonstrates "that even highly professional phishing infrastructures can be effectively combated." This sentiment was echoed by Benjamin Krause of the ZIT, who framed the takedown as a testament to the unit’s "disruptive" approach. This strategy prioritizes dismantling criminal services at their source rather than solely focusing on prosecuting individual perpetrators, aiming for a more impactful and lasting disruption of cybercriminal activities.
Remediation and Defense Strategies
Microsoft has initiated the process of notifying users who were impacted by the Kratos campaigns. The recommended remediation steps vary depending on the method of compromise. For victims whose credentials were only harvested, a password reset coupled with a Multi-Factor Authentication (MFA) check is generally sufficient. However, in cases where the kit’s reverse-proxy mode captured a live session, simply resetting the password is not enough. Such sessions must be actively revoked, and high-value accounts should be migrated to phishing-resistant sign-in methods.

Cybersecurity defenders can also employ technical indicators to identify potential Kratos activity. ANY.RUN’s analysis revealed that Kratos login pages frequently load specific paired assets, barr.svg and lg.svg, and subsequently POST stolen credentials to endpoints such as next.php or save.php. This distinctive pattern has been observed with a high degree of accuracy, offering a reliable method for detecting ongoing or past compromises.
The Evolving Threat Landscape
While the current takedown has effectively neutralized the Kratos infrastructure, the underlying threat remains. The approximately 1,800 customers who previously utilized the service, and potentially the kit’s code they have already acquired, pose an ongoing risk. Cybercriminal operations are known for their adaptability, frequently migrating to new domains, exploiting compromised websites, or sharing hosting with other malicious tools. It is highly probable that the Kratos code will reappear under a new name or in a modified form, underscoring the persistent and evolving nature of the cybercrime threat landscape.
The success of this international operation highlights the critical importance of cross-border collaboration in combating sophisticated cybercrime. The dismantling of Kratos serves as a potent reminder that while law enforcement efforts can significantly disrupt criminal enterprises, continuous vigilance and adaptive security measures are paramount for organizations and individuals alike to stay ahead of emerging threats. The fight against phishing and sophisticated credential theft is an ongoing battle, requiring sustained innovation in both offensive and defensive cybersecurity strategies.







