Police Dismantle Kratos — The Phishing Kit That Laughed at Two-Factor Authentication
German and US law enforcement have taken down the infrastructure behind Kratos, according to The Hacker News, seizing more than 200 servers and arresting the Indonesian developer believed to have built and operated it. German investigators describe it as one of the most widely deployed criminal phishing kits in the world.
The numbers are not small. Around 1,800 paying customers used Kratos to run approximately 15,000 phishing campaigns every month, targeting hundreds of thousands of victims across more than 30 countries since late 2024.
What made Kratos genuinely dangerous was its session-stealing capability. Most phishing kits grab your password and stop there. Kratos went further by also capturing the session cookie — the small file your browser holds after a successful login that tells Microsoft's servers you are already authenticated. An attacker holding that cookie can walk straight into your account without ever needing your password or your two-factor code, because to Microsoft's systems, they look exactly like you.
The kit offered two modes. A basic version harvested credentials only. The advanced version used an adversary-in-the-middle attack (where a hidden proxy sits between you and Microsoft, relaying your real login while quietly copying everything, including the live session) to capture that post-login cookie in real time. The whole thing was sold as a subscription service, paid in cryptocurrency, managed through a Telegram shop — low skill required.
Microsoft tracked the same kit under the name SneakyLog and caught a campaign in February targeting about 100 US organisations in manufacturing, retail, and healthcare, using fake W-2 tax documents with personalised QR codes.
The servers are offline. The roughly 1,800 customers and the kit code they already downloaded are not.
What you should do: If Microsoft contacts you about this campaign, do not just reset your password. Check whether any active sessions need to be revoked — especially for Microsoft 365 accounts. You can do this under your Microsoft account security settings at account.microsoft.com.
Sources

