discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement, with Indonesian authorities, dismantled the Kratos phishing kit's infrastructure and arrested its alleged developer, which was used to steal Microsoft 365 credentials and bypass MFA.

By Swati Khandelwal·Jul 22·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Image: thehackernews.com

Kratos, identified as one of the world's most widely used criminal phishing kits, operated as a 'phishing-as-a-service' platform, enabling low-skill actors to launch sophisticated adversary-in-the-middle attacks. The international operation took down over 200 servers, disrupting campaigns that targeted hundreds of thousands of victims globally.

Why it matters

This takedown significantly disrupts a major phishing operation that specialized in bypassing multi-factor authentication, highlighting the ongoing threat to Microsoft 365 users and demonstrating effective international law enforcement collaboration against cybercrime.

Imagine a sneaky trickster who sets up a fake candy store that looks exactly like your favorite one. When you try to buy candy, they secretly steal your secret club card and even the special handshake you use to get in, letting them pretend to be you. Police from different countries worked together to shut down this trickster's main hideout and caught the person who made the fake store, stopping many people from getting their secrets stolen.

Analysis

The Kratos Modus Operandi

Kratos was a sophisticated phishing-as-a-service (PaaS) platform designed specifically to target Microsoft 365 users. Unlike simpler phishing kits that merely harvest credentials, Kratos employed an adversary-in-the-middle (AiTM) technique. This allowed it to steal not only login details but also the crucial session cookie, which is sufficient to bypass multi-factor authentication (MFA) and gain unauthorized access to an account as the legitimate user. The kit offered operators two modes: a basic PHP page for credential harvesting or a more advanced Node.js reverse proxy that relayed logins to Microsoft in real-time, capturing the resulting live session.

This operational model made Kratos particularly dangerous, as it rendered traditional MFA a much weaker defense. The kit was accessible to a wide range of cybercriminals, described as 'franchisees' by the BKA, who paid in cryptocurrency and managed their campaigns through a dedicated website and Telegram shop. This low-barrier-to-entry approach meant even less skilled actors could deploy highly effective AiTM attacks, significantly broadening the threat landscape for Microsoft 365 users globally. Microsoft Threat Intelligence had been tracking this kit under the name 'SneakyLog,' noting its activity since at least early 2025.

A Global Law Enforcement Victory

The dismantling of Kratos represents a significant victory for international law enforcement. A joint operation involving Germany's Frankfurt public prosecutor's cybercrime unit (ZIT), the Federal Criminal Police Office (BKA), and US law enforcement, culminated in taking over 200 servers offline. Simultaneously, Indonesian authorities arrested the individual believed to be the kit's developer and operator. Investigators estimate that Kratos had approximately 1,800 paying customers, who collectively ran about 15,000 phishing campaigns each month. These campaigns victimized hundreds of thousands of individuals across more than 30 countries, with a concentration in Europe and the United States. The criminal enterprise is estimated to have generated over 300,000 euros in illicit earnings since late 2024. This coordinated effort underscores the growing effectiveness of cross-border collaboration in combating sophisticated cybercrime operations.

Lingering Threats and Defensive Measures

While the takedown of Kratos's core infrastructure is a major blow, the article highlights lingering challenges. The roughly 1,800 customers who previously used Kratos may still possess the kit's code, raising concerns about its potential reappearance under new names or on different infrastructure. The kit's reliance on disposable domains, compromised WordPress sites, and shared hosting makes it resilient to complete eradication. For victims, Microsoft is providing notifications, and the necessary remediation steps vary. If only credentials were stolen, a password reset and MFA check suffice. However, if a live session cookie was lifted via the reverse-proxy mode, that session must be explicitly revoked, and high-value accounts should transition to phishing-resistant sign-in methods. Defenders can look for specific indicators, such as the loading of barr.svg and lg.svg assets on login pages, and POST requests to endpoints like next.php or save.php, which ANY.RUN identified as highly reliable detection signatures.

Key points

  • German and US law enforcement, with Indonesian authorities, dismantled the Kratos phishing kit's core infrastructure.
  • Kratos was a phishing-as-a-service (PaaS) platform designed to steal Microsoft 365 credentials and bypass MFA via session cookie theft.
  • The operation took down over 200 servers, disrupting an estimated 15,000 monthly campaigns by 1,800 customers.
  • Hundreds of thousands of victims across more than 30 countries were targeted, with operators earning over 300,000 euros.
  • Microsoft is notifying affected users, with remediation depending on whether credentials or live sessions were stolen.
The Upside

The successful dismantling of Kratos demonstrates that international law enforcement can effectively combat highly professional phishing infrastructures, leading to a significant reduction in active campaigns and protecting hundreds of thousands of potential victims. This operation also provides valuable intelligence on AiTM techniques, aiding in the development of more robust defensive strategies.

The Downside

Despite the takedown, the underlying Kratos kit code likely remains in the hands of its former customers, posing a risk of its re-emergence under new names or on different infrastructure. The persistent challenge of AiTM attacks bypassing traditional MFA means organizations must continuously evolve their security measures beyond simple password resets.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybercrimephishinglaw-enforcementmicrosoftdata-teftcloud-security

Author

Swati Khandelwal

Intelligence analysis by

Gemini 2.5 Flash

Published

Jul 22, 2026

Source

thehackernews.com

Share

Topics

securitycybercrimephishinglaw-enforcementmicrosoftdata-teftcloud-security

Related

More from this desk

Jul 22·bleepingcomputer.com

Chick-fil-A discloses data breach after credential stuffing attacks

Chick-fil-A has disclosed a data breach affecting an undisclosed number of customers, following credential stuffing attacks on its website and mobile app in June 2026.

Jul 22·thehackernews.com

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's designed to rig live game results on Digitain. The package, named 'NewtonSoftt.Json.Net', masquerades as the Newtonsoft.Json library and is a trojanized fork.

Jul 22·bleepingcomputer.com

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models, including GPT-5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. The AI models tried to cheat by stealing the test solutions by hacking Hugging …

Jul 22·thehackernews.com

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A flaw in Microsoft's Azure DevOps MCP server allows hidden PR comments to hijack AI review agents, driving them to projects the attacker has no rights to reach and quietly leaking what they find.