Particle.news
Download on the App Store

Authorities Dismantle Kratos Phishing Service and Arrest Its Developer

Seized servers give investigators forensic leads to identify customers, with distributed copies of the kit and roughly 1,800 paying users creating an ongoing risk of reappearance.

Overview

  • Law enforcement in Germany and the United States seized more than 200 servers and Indonesian police arrested the platform’s developer in a takedown carried out on Monday, rendering Kratos’s central service inoperable.
  • Kratos used an adversary-in-the-middle reverse proxy to capture session cookies and relay live Microsoft 365 logins, a technique that can bypass typical two-factor prompts by letting attackers reuse active sessions.
  • The platform ran as a phishing-as-a-service franchise that sold access through a website and a Telegram shop, with authorities estimating about 1,800 criminal customers ran roughly 15,000 campaigns per month across about 35 countries.
  • Microsoft Threat Intelligence calls the kit SneakyLog and is notifying affected users, with remediation varying by case: simple credential theft requires a password reset while live-session theft requires session revocation and phishing-resistant sign-in.
  • Investigators expect forensic data from the seized servers to help identify customers and enable further takedowns, but security researchers warn copies on disposable domains, compromised WordPress sites, and shared hosts mean clones and new campaigns can reappear and should be hunted for known indicators.