← Back to Daily Briefing

A multinational law enforcement operation led by Germany's BKA and ZIT, in coordination with the US and Indonesia, has neutralized the Kratos (aka SneakyLog/Sneaky 2FA) Phishing-as-a-Service (PhaaS) infrastructure. The operation resulted in the seizure of over 200 servers and the arrest of a primary administrator in Indonesia. Kratos leveraged Adversary-in-the-Middle (AiTM) proxying to intercept Microsoft 365 authentication flows, enabling the theft of session tokens to bypass multi-factor authentication (MFA). While the backend infrastructure is offline, approximately 1,800 active affiliates retain access to target lists and may migrate to alternative PhaaS kits, maintaining the operational threat level.

  • Incident Overview: Infrastructure Neutralization

    • Multi-agency takedown targeting a scalable, subscription-based phishing ecosystem focused on Microsoft environments.
    • Seizure of 200+ distributed nodes across multiple jurisdictions to disrupt the "vendor" layer of the cybercrime supply chain.
    • Arrest of a key developer/administrator, providing a critical blow to the Kratos brand's operational capacity.
  • Attack Vector: AiTM & MFA Bypass

    • Deployment of Adversary-in-the-Middle (AiTM) proxy servers to intercept real-time traffic between victims and legitimate Microsoft 365 login portals.
    • Technical focus on session token theft, allowing attackers to hijack authenticated sessions and bypass traditional MFA.
    • Use of a software-as-a-service model to lower the barrier to entry for low-skill affiliates.
  • Ecosystem Scale & Intelligence Value

    • The platform supported a massive customer base of approximately 1,800 independent affiliates.
    • Seized customer lists provide high intelligence value for law enforcement to conduct downstream attribution and prosecution.
    • Disruption causes a temporary market shift as affiliates seek competing phishing kits to maintain their campaigns.
  • Strategic Counter-Perspectives: The "Hydra" Effect

    • Experts argue that the takedown is largely symbolic due to the ease of replicating software-based malicious operations.
    • The resilience of the threat persists because affiliates possess their own target lists independent of the Kratos vendor.
    • Identification of PhaaS as a decentralized "Hydra," where the removal of one provider does not eliminate the underlying demand or technical IP.
  • Defensive Implications & Conclusion

    • Underscores the critical need for phishing-resistant MFA (FIDO2/WebAuthn) to counter AiTM proxying.
    • Highlights the shift toward industrialized cybercrime, necessitating coordinated international legal responses over isolated technical blocks.
    • Emphasizes that infrastructure takedowns are a tactical victory, but systemic risk remains high due to the modular nature of modern phishing kits.

Related posts

  1. The Register - Security — Kratos phishing-as-a-service kit loses its battle with international law enforcement
  2. SC Media — German authorities dismantle Kratos phishing-as-a-service infrastructure
  3. feeds.feedburner.com — Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
  4. techjacksolutions.com — Kratos/SneakyLog Takedown Leaves 1,800 AiTM Kit Holders Active: What Microsoft 365 Defenders Must Do Now
  5. csoonline.com — German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
  6. Trendmicro
  7. Cyberpress
  8. Blog
  9. Helpnetsecurity
  10. Medium
  11. Ground
  12. Reddit

LINK COPIED TO CLIPBOARD