Cyber Security

Police Disband Kratos Hacking Kit Designed to Steal Microsoft 365 Sessions and Bypass MFA

ISwati KhandelwalJuly 22, 2026Law Enforcement / Cyber ​​Crime​​​​

German and US regulators have taken down the core infrastructure of Kratosdescribed by German investigators as one of the world’s most widely used phishing tools, and Indonesian authorities arrested the man they say developed and ran it.

In a joint announcement on Monday, the Frankfurt Public Prosecutor’s Office (ZIT) and Germany’s Federal Criminal Police Office (BKA) said they had taken more than 200 servers offline. Investigators estimate about 1,800 paying customers use Kratos to conduct about 15,000 phishing campaigns per month.

Kratos has more than just passwords. The kit is designed to steal a session and login cookie, and that cookie is enough to bypass two-factor authentication on an account as a user, BKA said.

ANY.RUN, which modified the kit, found that operators can choose one of two options: a blank PHP page that only accepts data, or a reverse Node.js proxy designed to transmit logins to Microsoft in real time and capture the resulting session. That second mode is a mid-range enemy system that made standard MFA a much weaker backstop than it looks.

The business ran as a franchise, with customers BKA called franchisees. They pay in cryptocurrency and sign up for a dedicated website and Telegram store to manage their accounts and organize campaigns, so even low-skilled actors can target a working AiTM kit.

Authorities put the number of victims as of late 2024 in the hundreds of thousands, spread across more than 30 countries and concentrated in Europe and the United States. They estimate that operators have received more than 300,000 euros since 2024, and that each campaign can hit several thousand recipients.

Kratos was already being tracked. Microsoft Threat Intelligence identifies the same kit as SneakyLoga phishing platform that claims to have stolen credentials and 2FA against Microsoft 365 since at least early 2025, and held one campaign.

On February 10, operators sent tax-themed emails to about 100 organizations, mostly in the US, across the manufacturing, retail, and healthcare sectors, each carrying a W-2 document with a personal QR code to the recipient that led to a fake Microsoft 365 login.

A stolen Microsoft login is rarely the end of the line. The BKA said the stolen information could be used for phishing, sold to other criminals, or turned into corporate property by distributing it to their Microsoft 365 environments, a common route from a single fraudulent inbox to a corporate email crisis.

Carsten Meywirth, head of the BKA’s cybercrime unit, said the operation shows “that even the infrastructure of phishing can be successfully fought.” ZIT’s Benjamin Krause cited it as evidence of the bureau’s “disturbing” approach to breaking up criminal activity directly rather than charging the people who run it.

Microsoft notifies users caught up in campaigns. For anyone Microsoft has informed, the fix depends on how they were hit. When the kit only harvests credentials, password reset and MFA checks cover it. When its reverse-proxy mode suggests a live session, that session survives a reset, and therefore must be revoked, with high-value accounts routed to phishing-resistant logins.

Exploit-hunting defenders can check what the kit says: ANY.RUN found its login pages almost always load the paired properties barr.svg and lg.svg, and SEND the stolen data to endpoints like next.php or save.php. It estimates that 90% recall matches with almost no false positives.

Currently, the servers are offline and, BKA says, Kratos-powered campaigns cannot continue. What will not affect the downgrade is the nearly 1,800 customers or kit code they already have. ANY.RUN found Kratos running on scrap domains, compromised WordPress sites, and shared hosting with other third-party adversaries, a type of setup that reappears under a new name when the servers go down.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button