Ethical Hacking News
Operation Kratos highlights the importance of global cooperation and swift action in dismantling sophisticated cybercrime operations. The takedown of this notorious phishing kit demonstrates the devastating impact of such attacks on individuals and organizations worldwide.
German authorities, along with Indonesian police, successfully dismantled the core infrastructure of the notorious phishing kit "Kratos" (also known as "SneakyLog"), a franchise that had been used in over 15,000 phishing campaigns per month. The operation resulted in the arrest of the individual believed to have developed and operated Kratos, making them one of the first people held accountable for creating such a phishing kit. Kratos was estimated to have earned over $300,000 through cryptocurrency transactions since 2024, with victims reported across 30 countries and hundreds of thousands of users affected. The authorities involved noted that even low-skill actors could use the Kratos infrastructure to launch successful phishing attacks, highlighting the importance of continuous vigilance against such threats. The operation shows that highly professional phishing infrastructures can be effectively combated, and it serves as a reminder for individuals and organizations to remain vigilant and proactive in protecting themselves from emerging threats.
The world of cybersecurity is constantly evolving, and new threats emerge every day. One such threat that has gained significant attention recently is the infamous phishing kit known as "Kratos." This malicious tool was designed to steal Microsoft 365 sessions and bypass two-factor authentication (MFA), allowing attackers to gain unauthorized access to sensitive information.
According to a joint announcement made by German law enforcement officials, including the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA), they have successfully dismantled the core infrastructure of Kratos. The operation was a culmination of months-long efforts by authorities to track down and bring to justice the individuals responsible for creating and running this phishing kit.
Kratos, also known as "SneakyLog," is described by German investigators as one of the world's most widely used criminal phishing kits. It has been estimated that roughly 1,800 paying customers were using Kratos to run about 15,000 phishing campaigns every month. These campaigns were designed to harvest more than just passwords; they also aimed to steal session cookies, which can be used to bypass MFA and gain access to accounts.
The operation was carried out in collaboration with Indonesian authorities, who arrested the man believed to have developed and operated Kratos. The arrest was a significant blow to the attackers, as it marked one of the first times that an individual had been held accountable for their role in creating such a notorious phishing kit.
The authorities involved in the operation noted that Kratos operated like a franchise, with customers referred to as "franchisees." These individuals paid in cryptocurrency and signed up through dedicated websites and Telegram shops to manage their accounts and organize campaigns. Even low-skill actors could use this infrastructure to launch successful phishing attacks.
The impact of Kratos was far-reaching, with victims estimated to be in the hundreds of thousands across more than 30 countries. The attackers earned over $300,000 since 2024, primarily through cryptocurrency transactions. Each campaign could hit several thousand recipients, making this a highly lucrative operation for those involved.
Microsoft Threat Intelligence identified Kratos as one of its most notable phishing kits, with operations dating back to at least early 2025. One notable example was a tax-themed email campaign sent to about 100 organizations in the US, primarily in manufacturing, retail, and healthcare. The emails carried a personalized QR code that led to a fake Microsoft 365 login.
The authorities involved in the operation noted that stolen Microsoft logins can often be used for further phishing or sold to other criminals. In some cases, the attackers could use the stolen credentials to gain a foothold inside companies by spreading through their Microsoft 365 environments.
Carsten Meywirth, head of the BKA's cybercrime division, commented on the operation, stating that it shows "that even highly professional phishing infrastructures can be effectively combated." Benjamin Krause, from the ZIT, added that the operation highlights the office's "disruptive" approach to dismantling criminal services rather than just charging those behind them.
The operation has also sparked awareness among Microsoft users. The company is notifying users who were caught in the campaigns and offering fixes depending on how they were hit. For victims of the plain PHP page mode, a password reset and MFA check should cover it. In cases where the reverse-proxy mode lifted a live session, that session survives the reset, requiring it to be revoked with high-value accounts moved to phishing-resistant sign-in.
Defenders can look for telltale signs of Kratos' presence in their campaigns, such as the use of paired assets barr.svg and lg.svg. ANY.RUN found that this pairing is nearly 90% recall with zero false positives, making it a useful identifier for those hunting exposure.
While the operation has had a significant impact on disrupting the Kratos phishing kit, there remains concern about its ongoing presence in the cyber landscape. The authorities noted that the roughly 1,800 customers and the kit's code were left untouched in the takedown. ANY.RUN found that Kratos ran on disposable domains, compromised WordPress sites, and shared hosting with other adversary-in-the-middle kits.
The existence of such infrastructure highlights the need for continuous vigilance against phishing attacks and the importance of effective cybersecurity measures to prevent such threats from emerging. The operation by German and US law enforcement serves as a reminder that even the most sophisticated cybercrime operations can be dismantled through cooperation, intelligence gathering, and swift action.
In conclusion, Operation Kratos marks a significant victory for global law enforcement in their efforts to combat phishing attacks. While this operation has brought attention to one notorious phishing kit, it also underscores the ongoing need for cybersecurity awareness and robust defenses against such threats. As the world of cybersecurity continues to evolve, it is essential that individuals and organizations remain vigilant and proactive in protecting themselves from emerging threats.
Operation Kratos: A Global Crackdown on a Notorious Phishing Kit
Related Information:
https://www.ethicalhackingnews.com/articles/Operation-Kratos-A-Global-Crackdown-on-a-Notorious-Phishing-Kit-ehn.shtml
https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
Published: Wed Jul 22 11:56:46 2026 by llama3.2 3B Q4_K_M