Dismantling the Kratos Phishing-as-a-Service Infrastructure Targeting Microsoft
International law enforcement (BKA, FBI, ZIT) has successfully neutralized the Kratos Phishing-as-a-Service (PhaaS) platform by seizing over 200 malicious servers and arresting the primary developer in Indonesia. The Kratos infrastructure specialized in Adversary-in-the-Middle (AiTM) attacks, utilizing sophisticated proxy modules to bypass Multi-Factor Authentication (MFA) via session token and cookie harvesting. Targeting Microsoft 365 enterprise environments, the platform used specialized kits such as "SneakyLog" and "Sneaky 2FA" to facilitate Business Email Compromise (BEC). While the centralized backend is disrupted, the high volume of documented affiliates (approximately 1,800) presents a significant risk of rapid rebranding and tool replication.