In a significant blow to the global cybercrime ecosystem, a joint operation spearheaded by German and US law enforcement agencies, in close collaboration with Indonesian authorities, has successfully dismantled the core infrastructure of "Kratos," identified by German investigators as one of the world’s most pervasive criminal phishing kits. The operation culminated in the arrest of the individual believed to be the developer and operator of the illicit service in Indonesia, alongside the critical takedown of over 200 servers globally. This coordinated effort marks a pivotal moment in the ongoing fight against sophisticated Phishing-as-a-Service (PhaaS) platforms that enable even low-skilled actors to execute highly effective cyberattacks, including those capable of bypassing multi-factor authentication (MFA).
The announcement, made on Monday, July 22, 2026, by the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), detailed the extensive reach and technical sophistication of the Kratos platform. Investigators estimate that approximately 1,800 paying customers leveraged Kratos to launch an alarming 15,000 phishing campaigns each month. These campaigns, designed with deceptive precision, have targeted hundreds of thousands of victims across more than 30 countries since late 2024, with a notable concentration in Europe and the United States. The operators of Kratos are believed to have amassed over 300,000 euros in illicit gains during this period, underscoring the lucrative nature of such criminal enterprises.
The Anatomy of Kratos: A Phishing-as-a-Service Powerhouse
Kratos distinguished itself in the crowded PhaaS market through its advanced capabilities, which extended far beyond simple credential harvesting. While many phishing kits aim solely to steal usernames and passwords, Kratos was engineered to pilfer session cookies alongside login credentials. This crucial distinction allowed its users to bypass multi-factor authentication (MFA) mechanisms, rendering what is often considered a robust security measure largely ineffective. The stolen session cookie effectively acts as a legitimate user’s identity, granting attackers direct access to accounts without needing to re-authenticate or solve an MFA challenge.
According to a detailed analysis by cybersecurity firm ANY.RUN, which successfully reverse-engineered the kit, Kratos offered its "franchisees" — as the BKA termed its customers — two primary operational modes. The first was a straightforward PHP page designed exclusively for harvesting credentials. The second, and far more insidious, was a Node.js reverse proxy. This sophisticated module was specifically designed to relay login attempts to legitimate services, such as Microsoft, in real time. During this relay, the proxy would intercept and capture the resulting session cookie, allowing the attacker to establish a live, authenticated session. This technique is known as an Adversary-in-the-Middle (AiTM) attack, and it has emerged as a significant threat to modern authentication protocols that rely heavily on MFA.

Microsoft Threat Intelligence had independently tracked the same kit under the moniker "SneakyLog," identifying it as a potent Phishing-as-a-Service platform responsible for credential and 2FA theft against Microsoft 365 environments since at least early 2025. This independent tracking highlights the widespread recognition of Kratos/SneakyLog as a major threat actor in the cyber landscape.
A Criminal "Franchise" Model
The operational model of Kratos mirrored that of a legitimate business, albeit one steeped in illicit activities. The platform functioned as a "franchise," enabling even individuals with minimal technical skills to deploy sophisticated AiTM attacks. Customers would pay for access to the service using cryptocurrency, managing their accounts and organizing their phishing campaigns through a dedicated website and a Telegram-based "shop." This user-friendly interface significantly lowered the barrier to entry for cybercriminals, allowing a broader spectrum of malicious actors to engage in highly effective phishing operations that would otherwise require considerable technical expertise.
The scale of this criminal enterprise was staggering. With 1,800 active customers, the kit facilitated an average of 15,000 phishing campaigns monthly. Each of these campaigns had the potential to reach several thousand recipients, multiplying the risk and impact across a vast user base. The estimated hundreds of thousands of victims since late 2024 underscore the profound and pervasive threat Kratos posed to individuals and organizations worldwide. The financial gains of over 300,000 euros since 2024, generated through subscriptions and usage fees, illustrate the powerful economic incentives driving such cybercrime operations.
Chronology of Detection, Operation, and Takedown
The timeline of Kratos’s activities and subsequent demise paints a clear picture of its insidious growth and the persistent efforts of cybersecurity researchers and law enforcement to counter it:
- Late 2024: Kratos’s operations begin to impact victims, marking the initial phase of its widespread deployment.
- Early 2025: Microsoft Threat Intelligence identifies the phishing kit, designating it as "SneakyLog," and begins tracking its use in credential and 2FA theft campaigns against Microsoft 365 users.
- March 2026: Microsoft observes a significant surge in tax-themed phishing campaigns utilizing SneakyLog. These campaigns are particularly potent during tax season, exploiting public anxiety and urgency.
- February 10, 2026 (specific campaign example): Microsoft records a targeted campaign where operators sent tax-themed emails to approximately 100 organizations, predominantly in the United States. These emails, masquerading as legitimate communications, contained W-2 documents embedded with personalized QR codes. Scanning these QR codes directed recipients to a fake Microsoft 365 login page, designed to capture credentials and session cookies. The targeted sectors included manufacturing, retail, and healthcare, highlighting the diverse range of industries vulnerable to such attacks.
- Prior to July 2026: German and US law enforcement, in conjunction with international partners, meticulously gather intelligence and coordinate the operational phase to identify and locate the core infrastructure and the alleged developer.
- July 22, 2026: The coordinated takedown operation is executed, resulting in the offline status of more than 200 servers and the arrest of the alleged developer by Indonesian authorities. The public announcement by the BKA and ZIT confirms the success of the multi-national effort.
Beyond Credentials: The Threat of Session Hijacking and Downstream Impact
The ability of Kratos to steal session cookies represents a critical evolution in phishing tactics. While a stolen password can be mitigated by a prompt password reset and MFA re-enrollment, a hijacked session cookie allows an attacker to maintain an active, authenticated connection to a user’s account even after a password reset. This means that if an attacker captures a live session cookie, they can continue to access the account as the legitimate user until that specific session is explicitly revoked by the service provider or the user.

The implications of such sophisticated account takeovers are far-reaching. Stolen Microsoft logins, for instance, are rarely the final objective for cybercriminals. The BKA highlighted several common downstream uses:
- Further Phishing: Attackers can leverage compromised accounts to launch more credible phishing attacks from within an organization’s trusted network, increasing the success rate of subsequent campaigns.
- Sale to Other Criminals: Access to legitimate accounts, especially those within corporate environments, is a valuable commodity on dark web marketplaces, traded for significant sums.
- Foothold for Business Email Compromise (BEC): A compromised email account within a company can serve as a springboard for sophisticated BEC scams. Attackers can monitor internal communications, impersonate executives, and initiate fraudulent financial transactions, leading to substantial monetary losses for businesses.
- Lateral Movement: Once inside a Microsoft 365 environment, attackers can use the compromised account to explore network directories, access sensitive documents, and potentially escalate privileges, moving laterally within the company’s digital infrastructure.
This chain of potential exploitation underscores why the takedown of Kratos, with its advanced session-hijacking capabilities, is so crucial in mitigating a wide array of cyber threats.
Official Reactions and Strategic Implications
Carsten Meywirth, who heads the BKA’s cybercrime division, lauded the operation as concrete proof "that even highly professional phishing infrastructures can be effectively combated." His statement reflects a growing confidence within law enforcement that persistent, coordinated international efforts can dismantle even the most entrenched criminal services.
Benjamin Krause of the ZIT further framed the operation as an embodiment of the office’s "disruptive" approach. This strategy focuses not merely on apprehending individuals but on actively dismantling the underlying infrastructure and services that enable cybercrime. By pulling over 200 servers offline and arresting the alleged developer, law enforcement has severely hampered Kratos’s operational capacity, at least temporarily. This disruptive tactic aims to increase the cost and complexity for cybercriminals, making it harder for them to operate and sustain their illicit businesses. The shift from purely reactive arrests to proactive infrastructure disruption is a strategic evolution in cybercrime fighting, recognizing the interconnected and adaptable nature of online criminal networks.
Guidance for Affected Users and Organizations
In the wake of the takedown, Microsoft is actively notifying users whose accounts may have been compromised by Kratos/SneakyLog campaigns. The recommended remediation steps vary depending on the nature of the compromise:

- For accounts where only credentials were harvested: A password reset, immediately followed by a thorough check of multi-factor authentication settings to ensure they are robust and active, is generally sufficient.
- For accounts where a live session cookie was lifted via the reverse-proxy mode: The situation demands more aggressive action. Since a stolen session can survive a password reset, it is imperative that the compromised session be explicitly revoked. For high-value accounts, Microsoft recommends transitioning to phishing-resistant sign-in methods, such as hardware security keys (e.g., FIDO2) or certificate-based authentication, which are far more resilient against AiTM attacks.
Furthermore, cybersecurity defenders within organizations can look for specific technical indicators to identify potential exposure to Kratos. ANY.RUN’s analysis revealed distinct "tells" for the kit: its login pages almost invariably load the paired assets barr.svg and lg.svg. Stolen credentials are then typically POSTed to endpoints such as next.php or save.php. ANY.RUN rates this specific pairing of indicators with a high recall rate of 90% and near-zero false positives, making it a reliable signature for detection.
The Enduring Challenge: Resiliency of Cybercrime Operations
While the takedown of Kratos’s core infrastructure is a significant victory, the fight against PhaaS platforms is an ongoing challenge. The BKA confirms that the servers are currently offline, and Kratos-powered campaigns cannot continue in their original form. However, the operation did not eradicate the roughly 1,800 customers who previously utilized the service, nor did it directly seize all copies of the kit code they may possess.
The nature of PhaaS operations often involves the use of disposable domains, compromised WordPress sites, and shared hosting environments, which makes them inherently resilient. Cybercrime groups frequently rebrand, repackage, and relaunch their services under new names and on new infrastructure once their previous operations are disrupted. This adaptability means that while Kratos may be temporarily out of commission, the underlying threat model and the demand for such services persist. It is highly probable that former Kratos customers, or even the original developer operating under a new alias, will seek to establish or migrate to similar PhaaS offerings.
This incident underscores the continuous need for vigilance, strong cybersecurity practices, and sustained international cooperation among law enforcement agencies and private sector security researchers. As cybercriminals evolve their tactics, so too must the defensive and disruptive strategies employed to protect individuals and organizations from their relentless attacks. The takedown of Kratos serves as a powerful reminder of the global nature of cybercrime and the effectiveness of a united front in confronting it, even as the landscape of threats continues to shift and evolve.
