Kratos Phishing Kit Dismantled: 200 Servers Down, But 1,800 Customers Still Have the Code
German and US law enforcement have pulled the plug on Kratos, a phishing-as-a-service operation that German investigators describe as one of the most widely used criminal toolkits in the world. Indonesian authorities arrested the man they believe built and ran the whole thing.
The Frankfurt cybercrime prosecutors (ZIT) and the BKA announced Monday they had taken more than 200 servers offline. At its peak, the platform had around 1,800 paying customers running roughly 15,000 phishing campaigns per month.
Kratos was not just a password harvester. The kit was built to steal session cookies alongside credentials. Grab the session cookie and MFA becomes largely irrelevant, because you are authenticating as the user after they have already proven who they are.
Security researchers at ANY.RUN reverse-engineered the kit and found two operating modes. The first is a straightforward PHP page that lifts credentials. The second is more dangerous: a Node.js reverse proxy that relays the victim's login to Microsoft in real time, capturing the live session token as it's issued. That is the adversary-in-the-middle technique that has been quietly making standard MFA look far more reliable than it actually is.
The business model was essentially a franchise. Customers, referred to by the BKA as franchisees, paid in cryptocurrency and managed campaigns through a dedicated website and a Telegram storefront. No technical sophistication required. Point the kit at a target list and go.
Since late 2024, authorities estimate hundreds of thousands of victims across more than 30 countries, mostly concentrated in Europe and the US. The operators are believed to have cleared over 300,000 euros, with individual campaigns capable of reaching several thousand recipients at a time.
Microsoft had already been tracking this under a different name. Its threat intelligence team calls it SneakyLog, flagging it as a phishing-as-a-service platform targeting Microsoft 365 since at least early 2025. Microsoft caught one campaign mid-operation: on February 10, tax-themed emails carrying fake W-2 documents hit roughly 100 organisations, mostly in the US across manufacturing, retail, and healthcare. Each email contained a QR code personalised to the recipient, leading to a convincing Microsoft 365 login page.
Stolen Microsoft credentials rarely sit unused. The BKA noted they typically get recycled into further phishing, sold on to other criminals, or used to burrow deeper into a company's Microsoft 365 environment, the well-worn route to business email compromise.
BKA cybercrime chief Carsten Meywirth said the operation demonstrates that even sophisticated phishing infrastructure can be dismantled effectively. ZIT's Benjamin Krause framed it as an example of the office's disruptive strategy, taking down the criminal service itself rather than simply charging the individuals running it.
Microsoft is notifying affected users. The remediation path depends on which mode hit them. If only credentials were stolen, a password reset and MFA review covers it. If the reverse proxy captured a live session, that session can survive a password reset entirely, so it needs to be explicitly revoked. High-value accounts should be moved to phishing-resistant authentication.
For defenders doing their own threat hunting, ANY.RUN identified a reliable fingerprint: Kratos login pages almost always load two paired image assets, barr.svg and lg.svg, before posting stolen data to endpoints like next.php or save.php. That combination reportedly gives 90% recall with near-zero false positives.
The servers are down and, for now, active Kratos campaigns cannot run. What the takedown did not address is the roughly 1,800 customers who already have the kit code. ANY.RUN found it deployed across throwaway domains, compromised WordPress sites, and infrastructure shared with other adversary-in-the-middle toolkits. That kind of setup does not disappear. It rebrands, finds new hosting, and comes back under a different name. Watch this space.