The record
Written from the 1 report below. Nothing here is unsourced.
- German and US law enforcement took down the core infrastructure of Kratos, one of the world's most widely used criminal phishing kits, seizing more than 200 servers, while Indonesian authorities arrested the alleged developer.
- The kit, sold to roughly 1,800 paying customers who ran about 15,000 phishing campaigns a month, stole Microsoft 365 credentials and session cookies, allowing attackers to bypass two-factor authentication and reach hundreds of thousands of victims in over 30 countries since late 2024.
- Investigators say the operators earned more than 300,000 euros since 2024, and stolen logins could enable business email compromise and further attacks.
- The takedown halts Kratos-powered campaigns for now, but its customers still hold the kit code, which could reappear under a new name.
What to watch next
- Whether Kratos customers redeploy the kit code on new infrastructure under a different name
- Reports of additional arrests or charges against the kit's franchisee customers
- Microsoft notifications to affected users and whether phishing-resistant sign-in is adopted for high-value accounts
Coverage1
1 report
English national1
All filed from India
Named Germany · United States · Indonesia · Microsoft · Microsoft 365 · ANY.RUN · Benjamin Krause · Carsten Meywirth · Federal Criminal Police Office (BKA) · Frankfurt Public Prosecutor's Office (ZIT) · Indonesian man · Kratos · SneakyLog
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
