Categorie: News

Authorities have killed Kratos, the PhaaS (phishing-as-a-service) kit that earned over €300,000

A major global police operation has led to the dismantling of Kratos, one of the most dangerous and widespread phishing-as-a-service platforms worldwide.

German authorities, aided by law enforcement agencies in the United States and Indonesia, have neutralized the IT infrastructure behind the malware and have arrested its alleged developer and administrator.

The operation delivers a hard blow to cybercrime, stopping a network that has proven capable of generating thousands of deceptive campaigns every month and of hitting hundreds of thousands of victims distributed across more than 30 different countries.

Farewell Kratos, the PhaaS kit has been dismantled by authorities

The Central Office for Countering Cybercrime in Frankfurt am Main (ZIT) and the Federal Criminal Police Office of Germany (BKA) led the complex investigative operation that allowed to take down more than 200 servers used by the criminals.

The success of the operation was consolidated in Indonesia through the arrest of the key technical figure behind the programming of the illegal service.

Official estimates indicate that since 2024 the Kratos kit has yielded illicit profits exceeding €300,000 to its operators, providing technological support to more than 1,800 different criminal enterprises.

Benjamin Krause, head of ZIT, emphasized that the targeted investigative approach aimed at physically disrupting illicit online platforms proves to be an extremely effective tool for ensuring greater cybersecurity on a large scale.

In line with this view, Carsten Meywirth of the BKA reiterated a strong message: those who attempt to steal online credentials cannot consider themselves safe, confirming the unwavering dedication of law enforcement in relentlessly combating these digital threats.

Why was Kratos so dangerous?

The extreme criticality of Kratos stemmed from its ability to provide, even to those with less programming experience, advanced tools to evade modern corporate protection systems, including the essential multi-factor authentication.

The kit automated the creation of false login pages, structured in an extremely realistic way and often camouflaged as portals belonging to well-known productivity and design platforms, such as Microsoft, Adobe, SharePoint, OneDrive and Canva.

Through these precise imitations, the system furtively extorted credentials, passwords and valuable session cookies. According to investigations conducted by Microsoft and various data security companies, the software package in the past has operated also under alternative names such as SneakyLog or Sneaky 2FA.

Analyses also suggest that this fraudulent architecture originated from the direct evolution of previous Trojan families.

Registering a massive volume of about 15,000 phishing campaigns created monthly, it is easy to see how every single attack carried with it the destructive capacity to compromise the sensitive data of thousands of individuals simultaneously.

A network of victims across Europe and the United States

International investigations indicate that the primary targets of buyers of this extensive attack architecture resided almost exclusively in Europe and the United States.

In the United States, illicit actions heavily hit the manufacturing, retail, and healthcare sectors.

Investigators also noted a high degree of customization in the lures used; for example, the extensive use of fake U.S. W-2 tax forms, a detail that highlights the attackers’ ability to tailor assaults to maximize the number of victims.

In Europe, the attackers’ focus instead fragmented, striking a wide spectrum of organizations, including industrial facilities, affiliated law firms, technical institutes, educational institutions, and a multitude of small and medium-sized enterprises.

The definitive shutdown of the domains and the complete dismantling of Kratos’ infrastructure represent, accordingly, a formidable milestone for protecting and safeguarding the confidential information of numerous international institutions.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

iQOO X: the concept with a 15,000 mAh battery and extreme hardware

iQOO pushes gaming smartphone concept even further and internally unveils the new concept phone iQOO…

10 minutes ago

One UI 9.5: leak images reveal a new design in Liquid Glass style

Clearly, underneath the new graphical changes there will still be Android 17. It should be…

17 hours ago

HyperOS 4 Global: build leaks reveal the first supported smartphones

Xiaomi officially unveiled HyperOS 4 on August 13, and, just a few hours after the…

18 hours ago

iPhone 18 pushed back to 2027: memory chips blamed

The rumors about a "split" launch for the new iPhone lineup are becoming increasingly tangible,…

19 hours ago

MediaWorld APP Days: 15% off thousands of products, only for the weekend!

One of the most anticipated events for those who keep an eye on MediaWorld's offers…

19 hours ago

POCO F9 Pro and Ultra: the new flagship models revealed in advance

POCO, the Xiaomi sub-brand that built its identity around the formula "top-of-the-line specs, mid-range price",…

21 hours ago