German and US law enforcement, in coordination with Indonesian authorities, have dismantled the infrastructure behind Kratos, a sophisticated phishing kit designed to steal Microsoft 365 session cookies and bypass multi-factor authentication (MFA). The operation, announced by the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), took down over 200 servers and led to the arrest of the kit’s developer in Indonesia.
Kratos, also tracked by Microsoft Threat Intelligence as SneakyLog, operated as a phishing-as-a-service platform since at least early 2025. It offered two modes: a simple PHP page for credential harvesting and a Node.js reverse proxy that performed adversary-in-the-middle (AiTM) attacks, capturing live session cookies to bypass MFA. The kit had approximately 1,800 paying customers who ran about 15,000 phishing campaigns monthly, targeting victims across 30 countries, primarily in Europe and the US. The operators earned over 300,000 euros since 2024.
Security firm ANY.RUN reverse-engineered the kit, identifying indicators such as the paired assets barr.svg and lg.svg on login pages, and POST requests to endpoints like next.php or save.php. The BKA noted that stolen credentials could be used for further phishing, sold to other criminals, or leveraged for business email compromise. Microsoft is notifying affected users, recommending password resets and MFA checks for credential-only theft, and session revocation for AiTM attacks.
While the takedown disrupted current campaigns, the kit’s code and customer base remain, posing a risk of resurgence under new names. The operation highlights the effectiveness of dismantling criminal infrastructure rather than solely pursuing individual actors.
Products: Microsoft 365
Original source: thehackernews.com