GBHackers

Police Dismantle Kratos Phishing-as-a-Service Platform and Take Down Over 200 Servers


Authorities from Germany, the United States, and Indonesia have dismantled the central infrastructure of Kratos, a major phishing-as-a-service (PhaaS) platform that enabled cybercriminals worldwide to conduct large-scale credential-harvesting campaigns.

The operation, announced by Germany’s Federal Criminal Police Office (BKA) and the Frankfurt am Main Public Prosecutor’s Office’s Central Office for Combating Internet Crime (ZIT), resulted in the neutralization of over 200 servers and the arrest of Kratos’ alleged developer and technical administrator in Indonesia.

Police Dismantle Kratos Platform

Kratos functioned as a criminal “digital construction kit,” providing subscribers with tools to create and manage convincing counterfeit Microsoft authentication pages.

These fraudulent sites mimicked legitimate Microsoft login portals, using spoofed sign-in forms to capture victims’ usernames, email addresses, passwords, and potentially multi-factor authentication data.

Stolen credentials could then be exploited for account takeovers, business email compromise, identity fraud, data theft, and subsequent intrusion activities.

Investigators identified Kratos as one of the world’s most widespread phishing services, operating under a PhaaS business model. Instead of conducting every campaign themselves, the operators leased the toolkit to other criminals, essentially turning phishing operations into a subscription-based franchise.

This model lowered the technical barriers for aspiring cybercriminals by providing ready-made phishing templates, infrastructure, campaign management functions, and impersonation capabilities.

From 2020 to 2024, the Kratos group is believed to have generated over €300,000 through sales and subscriptions. Law enforcement estimates that more than 1,800 criminal customers gained access to the platform, reportedly launching around 15,000 phishing campaigns each month.

Each campaign could potentially reach thousands of recipients across multiple regions. This scale underscores how commercialized phishing ecosystems can amplify the impact of a single threat service beyond its core operators.

The coordinated takedown identified approximately 850 victims across 35 countries, with most located in Europe and the United States. By disrupting the central technical components, authorities stated that Kratos-supported phishing campaigns can no longer be executed.

Seizure banners have been deployed across affected infrastructure, indicating that law enforcement now controls the domains and services previously used by the operation.

This disruption is significant because phishing kits targeting Microsoft accounts are highly valuable to threat actors. Microsoft 365 credentials often provide access to corporate email, cloud storage, collaboration platforms, financial workflows, and internal business communications.

Attackers routinely exploit compromised accounts to move laterally, distribute malware, conduct invoice fraud, or launch more credible phishing messages from trusted mailboxes.

Organizations should view this takedown as a temporary reduction in risk rather than the end of the threat. PhaaS operators and their affiliates can quickly migrate to alternative kits, domains, and hosting providers.

Defenders are advised to enforce phishing-resistant multi-factor authentication, prioritize FIDO2 security keys or passkeys where possible, monitor for unusual Microsoft 365 login activity, and train users to verify authentication URLs before entering their credentials.

Security teams should also review sign-in logs for unfamiliar IP addresses, impossible travel events, suspicious OAuth consent grants, and unexpected mailbox rule changes, common indicators of account compromise following credential phishing.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link