type: incident ยท created: 2026-07-23 ยท updated: 2026-07-23 ยท tags: [le-action, phishing-kit, mfa-bypass, cybercrime-group] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true
Kratos Phishing Kit Takedown
German and US law enforcement dismantled the Kratos phishing kit infrastructure โ one of the world's most widely used criminal phishing toolkits. The takedown involved more than 200 servers. Indonesian authorities arrested the suspected developer.
Overview
| Attribute | Detail |
|---|---|
| Kit | Kratos phishing kit |
| Targets | Microsoft 365 sessions |
| Key feature | Session cookie theft (MFA bypass) |
| Scale | ~1,800 paying customers, ~15,000 phishing campaigns/month |
| Infrastructure | 200+ servers taken down |
| LE action | German & US police (server takedown); Indonesian police (developer arrest) |
| Date | 2026-07-22 |
Significance
Kratos was designed to steal session cookies alongside credentials, allowing attackers to bypass multi-factor authentication (MFA) entirely. With an estimated 1,800 paying customers running approximately 15,000 phishing campaigns per month through the kit, it represented a significant criminal ecosystem.
Impact
- Massive disruption to phishing-as-a-service ecosystem
- Removal of a major MFA-bypass capability from the cybercrime market
- Demonstrates successful international law enforcement collaboration (Germany, US, Indonesia)
Related Pages
- Netnut Takedown โ Another major LE takedown of cybercrime-enabling infrastructure
- O Unc 066 โ Vishing threat actor also targeting M365 with MFA bypass