Law Enforcement Takes Down Kratos Phishing Kit Targeting Microsoft 365
German and US authorities dismantled the Kratos phishing kit, widely used to steal Microsoft 365 sessions and bypass MFA. An Indonesian developer has been arrested in connection with the operation.
TL;DR
- Kratos was a top-tier phishing kit used to target Microsoft 365 users.
- It could bypass multi-factor authentication (MFA) protections.
- Joint operation by German, US, and Indonesian law enforcement led to its takedown.
- Core infrastructure seized and one suspect arrested.
- Highlights ongoing risks from advanced phishing-as-a-service tools.
In a significant win against cybercriminal infrastructure, German and US law enforcement agencies have taken down the core components of the Kratos phishing kit. This toolkit had gained notoriety for its ability to steal Microsoft 365 login sessions and circumvent multi-factor authentication (MFA), making it a potent threat to enterprise security.
The takedown follows coordinated efforts between Germany’s Frankfurt public prosecutor's cybercrime unit (ZIT), the Federal Criminal Police Office (BKA), US partners, and Indonesian authorities who arrested the suspected operator. The disruption marks a major step in combating sophisticated phishing-as-a-service platforms that enable widespread business email compromise and credential theft.
What Made Kratos Dangerous
- Kratos specialized in harvesting Microsoft 365 credentials through realistic phishing pages.
- It featured advanced techniques to bypass MFA mechanisms, including real-time interception.
- Used by cybercriminals globally, it enabled large-scale access to corporate email accounts.
- Its modular design allowed attackers to customize attacks and evade detection.
Law Enforcement Action and Impact
- Authorities seized command-and-control servers and backend infrastructure.
- An individual in Indonesia was arrested on suspicion of developing and managing Kratos.
- Collaboration spanned multiple countries, reflecting the global nature of cybercrime.
- This takedown disrupts a critical tool in the phishing ecosystem, reducing immediate threats.
- Organizations should still audit for signs of past compromise and strengthen MFA policies.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.