German and US law enforcement have taken down the core infrastructure of Kratos, a phishing kit used in about 15,000 campaigns a month, while Indonesian authorities arrested the man they say developed and operated it.
KEY FACTS
- Servers seized More than 200 servers were taken offline.
- Scale Investigators estimate about 1,800 paying customers used the kit.
- Victims Authorities put the number of victims since late 2024 in the hundreds of thousands.
- Technique The kit stole credentials and session cookies to bypass two-factor authentication.
In a joint law enforcement disclosure, the Frankfurt public prosecutor’s cybercrime unit and Germany’s Federal Criminal Police Office said the operation disrupted a service sold through a dedicated website and Telegram shop. Customers paid in cryptocurrency and used the platform to manage campaigns.
The report said Kratos was built to steal both logins and session cookies, allowing attackers to move past two-factor authentication and into accounts as the user. It also said the kit could run in a simple PHP mode that collected credentials or a Node.js reverse proxy mode that relayed the login to Microsoft in real time and captured the resulting session.
Investigators said the operators earned more than 300,000 euros since 2024. They also said each campaign could target several thousand recipients, with attacks spread across more than 30 countries and concentrated in Europe and the United States.
Microsoft is notifying affected users, and the report says the response depends on the attack method. Where only credentials were taken, password resets and MFA checks are enough. Where a live session was captured, the session must also be revoked.
Defenders looking for exposure can check for the kit’s paired assets, barr.svg and lg.svg, and for posts to endpoints such as next.php or save.php. The report says the server takedown stops current Kratos campaigns, but it does not remove the code already held by customers.
WHY IT MATTERS
The takedown shows how phishing infrastructure can be disrupted even when it is run like a commercial service. It also underscores the risk from session theft, which can defeat standard multifactor authentication and lead to wider account compromise.

