Kratos PhaaS Group Dismantled in Major Law Enforcement Action

The Kratos phishing-as-a-service (PhaaS) group, a major supplier of adversary-in-the-middle phishing kits, has been dismantled following a global law enforcement operation. The takedown targeted the infrastructure behind Kratos, which has significantly impacted the phishing landscape in recent years.

Kratos PhaaS Takedown: Details of the Operation

On 26 July 2024, German authorities announced the seizure of over 200 servers linked to the Kratos PhaaS operation. The crackdown was coordinated by German law enforcement but involved agencies from the United States, Indonesia, and several other nations. In addition to seizing infrastructure, police arrested an unnamed individual in Indonesia described as a Kratos developer and technical administrator.

According to a statement from the German Federal Criminal Police Office, the Kratos infrastructure has been “completely disabled”. This means that, at least for the time being, Kratos-supported phishing campaigns cannot be carried out using the dismantled infrastructure.

  • Operation date: 26 July 2024
  • Lead agency: German Federal Criminal Police Office
  • International partners: United States, Indonesia and others
  • Servers seized: Over 200
  • Arrests: At least one developer/administrator in Indonesia

This action follows months of international cooperation and intelligence gathering, reflecting the scale and reach of Kratos within the cybercriminal ecosystem.

How Kratos Phishing-as-a-Service Worked

Kratos operated in the lucrative PhaaS market, supplying kits and infrastructure to at least 1,800 customers. The group’s core offering was sophisticated adversary-in-the-middle (AitM) phishing kits. These kits generated convincing fake Microsoft 365 login pages and were capable of harvesting session tokens, thereby bypassing multifactor authentication (MFA). This capability made Kratos kits particularly valuable for business email compromise (BEC) attacks.

  • Supplied phishing kits to over 1,800 customers
  • Focused on Microsoft 365 credential theft
  • Used AitM proxies to intercept session tokens
  • Enabled attackers to sidestep MFA protections

Kratos kits have been tracked under various names within the security community, including SneakyLog and Sneaky 2FA. Security researchers have noted that the renaming and reselling of PhaaS kits is common, making attribution and measurement of market share difficult. Despite this, there is consensus that Kratos was a major supplier within the phishing ecosystem.

The group did not conduct phishing campaigns directly. Instead, Kratos acted as a vendor, providing the tools and infrastructure for a broad base of cybercriminals to launch their own attacks. The customers retained their own target lists, sending infrastructure and any access achieved prior to the takedown.

Impact and Limitations of the Kratos Takedown

While the seizure of Kratos infrastructure and arrest of a key developer marks a significant disruption, analysts caution against expecting a major drop in global phishing activity. Experts like Frank Dickson, Group VP for Security at IDC, point out that server seizures remove infrastructure, not the underlying intellectual property. PhaaS kits are routinely cloned, forked and resold, meaning the market can quickly adapt to the loss of a major vendor.

Noah Kenney, Principal Consultant at Digital 520, emphasises that Kratos was simply a supplier. The customers who purchased Kratos kits still have their own resources and are likely to seek alternative vendors in the active PhaaS market. In effect, the phishing campaigns targeting enterprises and individuals are expected to continue, as attackers migrate to other platforms.

However, the arrest of a developer may temporarily slow the development and support of Kratos-style AitM phishing kits. Standing up new infrastructure is relatively easy, but replacing a skilled developer who maintained stable, evasive proxies at scale is more challenging. This could delay the resurgence of Kratos-branded kits, but similar tools are already available elsewhere.

One of the most valuable results of this operation may be the intelligence gained from the seized servers. Law enforcement now has access to customer lists and other operational data, which could inform further investigative actions against Kratos users and affiliated threat actors.

  • Immediate disruption of Kratos supply chain
  • Potential for further law enforcement action using seized data
  • Limited lasting effect on overall phishing volumes
  • Rapid replacement of vendors likely

Why This Matters for Organisations Using Microsoft 365

The takedown is significant because Kratos was behind a substantial portion of recent AitM phishing campaigns, especially those targeting Microsoft 365 accounts. These attacks are designed to defeat MFA and have been linked to large-scale business email compromise incidents.

UK small and medium businesses (SMBs) and enterprises should be aware that the disruption of Kratos is unlikely to reduce phishing risk in the near future. Attackers can quickly switch to other vendors, and the techniques pioneered by Kratos remain in circulation.

What Organisations Should Do Now

In light of this event, organisations should:

  • Continue to monitor for AitM phishing activity targeting Microsoft 365
  • Review and harden MFA implementations
  • Stay informed about developments resulting from law enforcement use of seized data

While the Kratos takedown is a positive step, ongoing vigilance and adaptation to evolving phishing tools and tactics remain essential.

Originally reported by csoonline.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins
Category
Phishing & Social Engineering
Published
Jul 23 - 2026
Post Tags
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call