German and US law enforcement have dismantled the Kratos phishing-as-a-service platform, a Microsoft 365 credential-theft kit that investigators say helped run roughly 15,000 phishing campaigns every month. The takedown is useful news for defenders, but it should not be treated as a cleanup signal for accounts that may already have been phished.[1]
The Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA) said the operation disabled more than 200 Kratos servers and led to the arrest of the alleged developer and technical administrator in Indonesia. Authorities described Kratos as one of the most widely used criminal phishing services, with more than 1,800 suspected criminal customers and victims in more than 30 countries since late 2024.[1]
Kratos mattered because it packaged convincing Microsoft sign-in pages, campaign management, Telegram-based sales and support, cryptocurrency payments, and deployment tooling into a rented service. That lowered the skill required to launch Microsoft 365 phishing, much like earlier account-takeover campaigns covered in our Evilginx Microsoft 365 phishing and ACR Stealer token-theft reports.
What Microsoft 365 defenders should check now
The most important detail is not only that passwords were stolen. BKA said Kratos was designed to capture a cookie along with login data, allowing attackers to bypass two-factor authentication in some cases.[1] The Hacker News, citing BKA and industry research, reported that the kit could operate as either a basic credential harvester or a reverse-proxy adversary-in-the-middle setup that relays a real login and captures the resulting session.[2]
That distinction changes incident response. If a victim only typed a password into a fake form, a password reset, MFA verification, and mailbox-rule review may be enough. If the campaign stole a live session or refresh token, resetting the password alone may leave the attacker authenticated. Admins should revoke sessions and refresh tokens, check recent sign-ins for impossible travel or unfamiliar devices, review OAuth app grants, inspect inbox forwarding rules, and examine SharePoint or OneDrive access around the suspected phishing window.
ANY.RUN’s July 14 technical analysis gives defenders practical fingerprints for retrospective hunting. Researchers linked Kratos to 1,628 sandbox sessions across its newer generations and identified the paired assets barr.svg and lg.svg as the strongest V1 signal, with V2 using a different cluster that includes dsa.svg, sid.gif, and imag.jpg. The same report lists exfiltration paths such as next.php, nex.php, n3xt.php, and save.php, plus Cloudflare Turnstile and fake Microsoft authentication behavior as useful supporting signals.[3]
Those indicators should be used carefully. Disposable attacker domains can usually be blocked, but broad Cloudflare infrastructure, shared cloud providers, and compromised legitimate sites require review before blocking. A better triage model is to score multiple signals together: Microsoft-themed login pages reached through SharePoint or OneDrive lures, Turnstile before the login form, Kratos asset pairs, suspicious POSTs to the collection endpoints, and session anomalies in Entra ID logs.
Microsoft is notifying affected users, according to the German authorities.[1] Organizations should not wait for a notice if users recently reported Microsoft 365 document-share emails, invoice lures, DocuSign-style messages, or fake CAPTCHA/anti-bot gates. Similar social-engineering patterns also appear in ClickFix-style attacks, including the UAC-0145 fake CAPTCHA malware campaign, where a trusted-looking interaction is used to move the victim into a credential or malware trap.
The takedown removes a major service from the phishing market, but it does not invalidate stolen credentials, mail rules, delegated app permissions, or sessions already issued before the servers went dark. For Microsoft 365 tenants, the practical takeaway is simple: treat any Kratos-linked alert as an account-takeover investigation, not as a normal password reset ticket.
References
- Bundeskriminalamt / Presseportal. “BKA: Erfolgreicher Schlag gegen eine der weltweit gefährlichsten Phishing-Gruppierungen.” July 20, 2026. https://www.presseportal.de/blaulicht/pm/7/6318131
- The Hacker News. “Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA.” July 22, 2026. https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
- ANY.RUN. “Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk.” July 14, 2026. https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/
- BleepingComputer. “Police dismantle Kratos phishing platform, arrest developer.” July 21, 2026. https://www.bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer/
Leave a Comment