Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-23 ยท updated: 2026-07-23 ยท tags: [le-action, phishing-kit, mfa-bypass, cybercrime-group] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare] ยท au_impact: true

Kratos Phishing Kit Takedown

German and US law enforcement dismantled the Kratos phishing kit infrastructure โ€” one of the world's most widely used criminal phishing toolkits. The takedown involved more than 200 servers. Indonesian authorities arrested the suspected developer.

Overview

Attribute Detail
Kit Kratos phishing kit
Targets Microsoft 365 sessions
Key feature Session cookie theft (MFA bypass)
Scale ~1,800 paying customers, ~15,000 phishing campaigns/month
Infrastructure 200+ servers taken down
LE action German & US police (server takedown); Indonesian police (developer arrest)
Date 2026-07-22

Significance

Kratos was designed to steal session cookies alongside credentials, allowing attackers to bypass multi-factor authentication (MFA) entirely. With an estimated 1,800 paying customers running approximately 15,000 phishing campaigns per month through the kit, it represented a significant criminal ecosystem.

Impact

  • Massive disruption to phishing-as-a-service ecosystem
  • Removal of a major MFA-bypass capability from the cybercrime market
  • Demonstrates successful international law enforcement collaboration (Germany, US, Indonesia)

Related Pages

  • Netnut Takedown โ€” Another major LE takedown of cybercrime-enabling infrastructure
  • O Unc 066 โ€” Vishing threat actor also targeting M365 with MFA bypass