German and American law enforcement have dismantled the core infrastructure of Kratos, a phishing-as-a-service platform investigators describe as one of the most widely used criminal phishing kits in the world, seizing more than 200 servers and arresting the man authorities say built and ran it, in Indonesia. The takedown targets a tool capable of defeating multi-factor authentication entirely, not merely stealing passwords, a distinction that has made it especially valuable to cybercriminals worldwide.
A Kit Built to Beat MFA, Not Just Steal Passwords
The joint operation, announced by the Frankfurt public prosecutor’s cybercrime unit and Germany’s Federal Criminal Police Office, targeted infrastructure that investigators estimate supported around 1,800 paying customers running roughly 15,000 phishing campaigns every month. What set Kratos apart from ordinary credential-harvesting kits was its ability to steal a victim’s active login session, not just their username and password, effectively letting attackers walk past two-factor authentication as though they were the legitimate user.
Security researchers who reverse-engineered the kit found operators could choose between two modes: a basic page that only captured credentials, or a more dangerous reverse-proxy mode that relayed the victim’s login to Microsoft in real time while quietly capturing the resulting session token. That second method, known as adversary-in-the-middle phishing, is precisely why standard MFA, the kind based on one-time codes or app approvals, has become a far weaker safeguard against modern phishing than most users assume.
Run Like a Criminal Franchise
Investigators described Kratos’s business model as functioning almost exactly like a franchise operation. Customers, whom German police referred to as franchisees, paid in cryptocurrency and signed up through a dedicated website and a Telegram-based shop to manage their accounts and organise campaigns, a setup that let even low-skill attackers deploy a fully functional session-hijacking kit without any technical expertise of their own.
Authorities estimate the operation has affected hundreds of thousands of victims across more than 30 countries since late 2024, concentrated primarily in Europe and the United States, generating over €300,000 in revenue for its operators. One documented campaign in February sent tax-themed phishing emails to around 100 organisations, mostly in the US manufacturing, retail and healthcare sectors, each carrying a personalised QR code leading to a convincing fake Microsoft 365 login page.
Already on Microsoft’s Radar
Kratos had not gone entirely unnoticed before the takedown. Microsoft’s own threat intelligence team had been tracking the same kit under the name SneakyLog, identifying it as a phishing-as-a-service platform running credential-and-2FA theft campaigns against Microsoft 365 users since at least early 2025, and had documented at least one tax-season campaign in the act earlier this year.
BKA cybercrime division head Carsten Meywirth said the operation demonstrated that even highly professional phishing infrastructure can be effectively disrupted, while Frankfurt prosecutor Benjamin Krause framed the approach as deliberately aimed at dismantling the criminal service itself, rather than only pursuing charges against individual users of the kit.
Why This Matters Beyond Europe and the US
Microsoft 365 accounts sit at the centre of email, file storage, payment conversations and internal business communication for organisations worldwide, including a large and growing base of Indian enterprises that rely on the platform for day-to-day operations. A single compromised account of this kind is rarely the end goal for attackers; it typically becomes a launchpad for further phishing from a trusted mailbox, lateral movement inside a company’s network, or invoice and payment fraud of exactly the kind Indian investigators have documented in recent business email compromise cases involving forged supplier bank details and spoofed internal emails.
Security researchers caution that the takedown, while significant, has not eliminated the threat. The roughly 1,800 customers who used Kratos, along with the underlying kit code many likely retain, remain unaddressed, and the kit was already found sharing hosting infrastructure with other adversary-in-the-middle phishing families such as Tycoon, Flowerstorm and EvilProxy, the kind of overlapping ecosystem that tends to resurface under a new name once one operation goes offline.
What Affected Organisations Should Do
Microsoft is directly notifying users caught up in Kratos campaigns, though the appropriate fix depends on how they were targeted. Where only credentials were harvested, a password reset combined with an MFA check is sufficient. Where the reverse-proxy mode captured a live session, that session survives a simple password reset and must be explicitly revoked, with high-value accounts ideally moved to phishing-resistant sign-in methods such as hardware security keys. Security teams more broadly are advised to monitor for unusual Microsoft 365 login activity and train users to verify authentication URLs before entering credentials, since kits like Kratos are built specifically to make fake login pages indistinguishable from genuine ones.
