• 2 min read
Kratos phishing kit taken down after 200 servers seized
German authorities say they dismantled key Kratos phishing infrastructure, seized more than 200 servers, and arrested an alleged developer in Indonesia.

Image: The Register
German authorities say they have neutralized the core infrastructure behind Kratos, a widely used phishing-as-a-service (PhaaS) kit, in an operation backed by the US and Indonesia. The takedown included more than 200 servers, while Indonesian authorities arrested the alleged developer and technical administrator of the platform.
According to Frankfurt am Main’s Central Office for Combating Internet Crime (ZIT) and Germany’s Federal Criminal Police (BKA), Kratos was one of the most widespread and dangerous PhaaS kits on the market. Investigators said it let low-skill criminals steal credentials — including passwords and session cookies — using convincing Microsoft-themed phishing pages that could help bypass MFA.
German authorities said criminals using Kratos targeted hundreds of thousands of victims in more than 30 countries. The operation behind the kit allegedly earned more than €300,000 ($342,000) since 2024, with an estimated 1,800 criminal enterprises using the service and running around 15,000 phishing campaigns per month.

Recommended reading
Hackers Are Hiding Malware in AI Dev Pipelines
“Each individual campaign had the potential to harm several thousand recipients worldwide.”
The ZIT and BKA did not explain how the servers were neutralized. Previous takedowns have involved legal orders to hosting providers and cooperation with ISPs to sinkhole or null-route traffic tied to suspect IP addresses.
Dr Benjamin Krause, head of the ZIT at the Frankfurt am Main Public Prosecutor’s Office, said the case showed that “disruptive law enforcement works.” Carsten Meywirth, head of the cybercrime department at the BKA, added that the result should serve as a warning to other phishing operators.
Kratos, SneakyLog, and conflicting timelines
German authorities referred to the kit only as Kratos, but open source reporting has linked it to products sold under names including SneakyLog and Sneaky 2FA. The exact history is murky.
Microsoft said earlier this year that SneakyLog had been used in phishing campaigns targeting US citizens with fake W-2 tax forms. On July 16, Heal Security reported that Kratos offered phishing templates themed around SharePoint, OneDrive, Microsoft Forms, Canva, and Tilda. KnowBe4 said in February that it had also seen Adobe lures.
The timelines do not fully line up. Microsoft said SneakyLog entered the phishing-kit market in early 2025, while KnowBe4 said the first signs of Kratos appeared only in January 2026. KnowBe4 also argued that Kratos evolved from a family of commercial trojans and infostealers, rather than explicitly tying it to SneakyLog or Sneaky 2FA.
What does appear consistent across public reports is the target base: mainly victims in the US and Europe. Microsoft identified manufacturing, retail, and healthcare as key US targets, while ANY.RUN said attacks in Europe hit industrial organizations, law firms, polytechnic institutions, schools, SMBs, and others.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via The Register


