Kratos phishing-as-a-service kit loses its battle with international law enforcement

← Back to the feed

Kratos phishing-as-a-service kit loses its battle with international law enforcement

The Register · 5 hours ago

German police, working with US and Indonesian authorities, have dismantled the core infrastructure behind Kratos, a phishing-as-a-service kit described as one of the most widespread and dangerous on the market. The alleged developer and technical administrator of the kit was arrested in Indonesia, though officials have not said whether other suspects are being pursued. The takedown matters because Kratos made it easy for low-skill criminals to run convincing Microsoft-themed phishing campaigns capable of stealing passwords and session cookies to bypass multi-factor authentication.

Frankfurt's Central Office for Combating Internet Crime (ZIT) and the Federal Criminal Police Office (BKA) said more than 1,800 criminal enterprises used Kratos to run around 15,000 phishing campaigns a month, targeting hundreds of thousands of victims in over 30 countries and earning operators more than €300,000 since 2024. Investigators neutralised over 200 servers but did not disclose their methods, though past operations have involved serving legal warrants to hosting providers and working with ISPs to sinkhole malicious traffic. Open-source research has linked Kratos to previously known kits such as SneakyLog and Sneaky 2FA, which have also been used for lures impersonating SharePoint, OneDrive, Canva and Adobe, among others.

  • Germany, US and Indonesia dismantled the Kratos phishing kit's infrastructure.
  • Alleged developer arrested in Indonesia; over 200 servers taken down.
  • Kit was used by 1,800+ criminal groups, earning over €300,000 since 2024.

Cybersecurity Software Technology

Read the full article at the source →