← All stories
● Covered by 2 sources · 2 reportsMedium impact

Authorities Shut Down Kratos Phishing-as-a-Service Platform, Arrest Developer

🔄 Updated 72d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Kratos phishing platform dismantled, developer arrested in Indonesia.
  • Platform used for phishing Microsoft 365, bypassing MFA.
  • 15,000 phishing campaigns monthly by 1,800 customers.
  • Operation led by German and U.S. authorities, seizing over 200 servers.
  • Kratos was a major threat affecting 35 countries.

Kratos Phishing Platform Dismantled

German and U.S. authorities have dismantled the Kratos phishing-as-a-service platform, which was significantly affecting global cybersecurity due to its capabilities. The developer of Kratos was arrested in Indonesia as part of this operation. More than 200 servers were taken offline, disrupting the service's operations.

Impact of Kratos on Cybersecurity

Kratos was extensively used to conduct phishing campaigns, targeting Microsoft 365 accounts with approximately 15,000 campaigns per month. The platform was rented by around 1,800 criminal customers, making it a widely used service for impersonating Microsoft authentication pages to steal credentials and session cookies.

Security Vulnerabilities Exploited

The phishing toolkit's effectiveness was partly due to its ability to bypass multifactor authentication (MFA). The adversary-in-the-middle tactic exploited session cookies to gain unauthorized access, making the platform a significant threat to users’ security.

Operation Details

The operation was led by Germany's Prosecutor General Office and Federal Police, in collaboration with U.S. law enforcement agencies. This international effort underscores the severity of the threat posed by Kratos, which affected victims in 35 countries, particularly in Europe and the United States.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

German and US law enforcement dismantled the Kratos phishing kit, disrupting over 15,000 campaigns monthly. This kit exploited session cookies to bypass MFA, posing serious risks to Microsoft 365 accounts.

German and U.S. authorities shut down the Kratos phishing-as-a-service platform, arresting its developer in Indonesia. This disruption is significant due to Kratos' extensive use, with customers allegedly conducting around 15,000 phishing campaigns monthly across 35 countries.