German and United States law enforcement agencies have dismantled the core infrastructure of Kratos, a phishing kit described by German investigators as one of the world’s most widely used criminal phishing platforms. The operation was carried out in coordination with Indonesian authorities, who also detained the individual accused of developing and operating the service. In a joint announcement, the Frankfurt Public Prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA) confirmed that more than 200 servers linked to the phishing operation had been taken offline. Investigators estimate that approximately 1,800 paying customers used Kratos to conduct nearly 15,000 phishing campaigns every month. Authorities believe the platform has been active since late 2024 and has affected hundreds of thousands of victims across more than 30 countries, with the majority of attacks targeting users in Europe and the United States. Officials also estimate that the operators generated more than €300,000 in revenue since 2024 through cryptocurrency payments made by customers using the phishing service.
According to investigators, Kratos was designed to steal more than usernames and passwords. The phishing kit was capable of capturing active Microsoft 365 session cookies, allowing attackers to gain access to user accounts even after multi factor authentication had been completed. Germany’s BKA stated that possession of a valid session cookie enabled attackers to bypass two factor authentication and access accounts as legitimate users. Security researchers at ANY.RUN, who analyzed the phishing kit, found that Kratos supported two operational modes. One used a standard PHP based phishing page that collected login credentials, while the second relied on a Node.js reverse proxy that relayed authentication requests to Microsoft in real time before capturing the resulting session cookie. This second method used an adversary in the middle technique that significantly reduced the effectiveness of conventional multi factor authentication protections. The platform operated as a phishing as a service offering, allowing customers, referred to by investigators as franchisees, to register through a dedicated website and Telegram shop where they could manage subscriptions and launch phishing campaigns with limited technical expertise.
Microsoft Threat Intelligence has also been tracking the phishing platform under the name SneakyLog and reported that it has been used to steal Microsoft 365 credentials and authentication sessions since at least early 2025. One documented campaign occurred on February 10 when attackers distributed tax themed emails containing personalized QR codes embedded in W 2 documents. The campaign targeted around 100 organizations, primarily in the United States, including businesses operating in the manufacturing, retail, and healthcare sectors. Victims who scanned the QR codes were directed to fraudulent Microsoft 365 login pages designed to capture credentials and authentication sessions. According to BKA, stolen Microsoft 365 accounts can subsequently be used to conduct additional phishing attacks, sold on criminal marketplaces, or exploited to gain deeper access into corporate environments through business email compromise attacks. Carsten Meywirth, head of BKA’s cybercrime division, said the international operation demonstrated that even highly organized phishing infrastructures could be effectively disrupted. Benjamin Krause of ZIT stated that the operation reflected the organization’s strategy of dismantling criminal services rather than focusing solely on prosecuting individual operators.
Microsoft confirmed that it is notifying users identified as victims of the phishing campaigns and outlined different recovery measures depending on the attack method used. For incidents involving only credential theft, Microsoft recommends resetting passwords and reviewing multi factor authentication settings. However, where attackers obtained active session cookies through the reverse proxy technique, affected sessions must also be revoked because they remain valid even after passwords are changed. Microsoft also recommends moving high value accounts to phishing resistant authentication methods for stronger protection. Security researchers at ANY.RUN advised defenders to look for indicators associated with the phishing kit, including login pages that load the files barr.svg and lg.svg before sending stolen credentials to endpoints such as next.php or save.php. While German authorities stated that Kratos powered phishing campaigns cannot continue because the infrastructure has been dismantled, investigators also noted that many of the approximately 1,800 customers may still possess copies of the phishing kit. Researchers further observed that Kratos had been hosted on disposable domains, compromised WordPress websites, and infrastructure shared with other adversary in the middle phishing kits, indicating that similar operations may reappear under different names in the future.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.