A multinational law enforcement operation led by Germany's BKA and ZIT, in coordination with the US and Indonesia, has neutralized the Kratos (aka SneakyLog/Sneaky 2FA) Phishing-as-a-Service (PhaaS) infrastructure. The operation resulted in the seizure of over 200 servers and the arrest of a primary administrator in Indonesia. Kratos leveraged Adversary-in-the-Middle (AiTM) proxying to intercept Microsoft 365 authentication flows, enabling the theft of session tokens to bypass multi-factor authentication (MFA). While the backend infrastructure is offline, approximately 1,800 active affiliates retain access to target lists and may migrate to alternative PhaaS kits, maintaining the operational threat level.
-
Incident Overview: Infrastructure Neutralization
- Multi-agency takedown targeting a scalable, subscription-based phishing ecosystem focused on Microsoft environments.
- Seizure of 200+ distributed nodes across multiple jurisdictions to disrupt the "vendor" layer of the cybercrime supply chain.
- Arrest of a key developer/administrator, providing a critical blow to the Kratos brand's operational capacity.
-
Attack Vector: AiTM & MFA Bypass
- Deployment of Adversary-in-the-Middle (AiTM) proxy servers to intercept real-time traffic between victims and legitimate Microsoft 365 login portals.
- Technical focus on session token theft, allowing attackers to hijack authenticated sessions and bypass traditional MFA.
- Use of a software-as-a-service model to lower the barrier to entry for low-skill affiliates.
-
Ecosystem Scale & Intelligence Value
- The platform supported a massive customer base of approximately 1,800 independent affiliates.
- Seized customer lists provide high intelligence value for law enforcement to conduct downstream attribution and prosecution.
- Disruption causes a temporary market shift as affiliates seek competing phishing kits to maintain their campaigns.
-
Strategic Counter-Perspectives: The "Hydra" Effect
- Experts argue that the takedown is largely symbolic due to the ease of replicating software-based malicious operations.
- The resilience of the threat persists because affiliates possess their own target lists independent of the Kratos vendor.
- Identification of PhaaS as a decentralized "Hydra," where the removal of one provider does not eliminate the underlying demand or technical IP.
-
Defensive Implications & Conclusion
- Underscores the critical need for phishing-resistant MFA (FIDO2/WebAuthn) to counter AiTM proxying.
- Highlights the shift toward industrialized cybercrime, necessitating coordinated international legal responses over isolated technical blocks.
- Emphasizes that infrastructure takedowns are a tactical victory, but systemic risk remains high due to the modular nature of modern phishing kits.
Related posts
- The Register - Security — Kratos phishing-as-a-service kit loses its battle with international law enforcement
- SC Media — German authorities dismantle Kratos phishing-as-a-service infrastructure
- feeds.feedburner.com — Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
- techjacksolutions.com — Kratos/SneakyLog Takedown Leaves 1,800 AiTM Kit Holders Active: What Microsoft 365 Defenders Must Do Now
- csoonline.com — German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
- Trendmicro
- Cyberpress
- Blog
- Helpnetsecurity
- Medium
- Ground