Categorie: News

Authorities have killed Kratos, the PhaaS (phishing-as-a-service) kit that earned over €300,000

A major global police operation has led to the dismantling of Kratos, one of the most dangerous and widespread phishing-as-a-service platforms worldwide.

German authorities, aided by law enforcement agencies in the United States and Indonesia, have neutralized the IT infrastructure behind the malware and have arrested its alleged developer and administrator.

The operation delivers a hard blow to cybercrime, stopping a network that has proven capable of generating thousands of deceptive campaigns every month and of hitting hundreds of thousands of victims distributed across more than 30 different countries.

Farewell Kratos, the PhaaS kit has been dismantled by authorities

The Central Office for Countering Cybercrime in Frankfurt am Main (ZIT) and the Federal Criminal Police Office of Germany (BKA) led the complex investigative operation that allowed to take down more than 200 servers used by the criminals.

The success of the operation was consolidated in Indonesia through the arrest of the key technical figure behind the programming of the illegal service.

Official estimates indicate that since 2024 the Kratos kit has yielded illicit profits exceeding €300,000 to its operators, providing technological support to more than 1,800 different criminal enterprises.

Benjamin Krause, head of ZIT, emphasized that the targeted investigative approach aimed at physically disrupting illicit online platforms proves to be an extremely effective tool for ensuring greater cybersecurity on a large scale.

In line with this view, Carsten Meywirth of the BKA reiterated a strong message: those who attempt to steal online credentials cannot consider themselves safe, confirming the unwavering dedication of law enforcement in relentlessly combating these digital threats.

Why was Kratos so dangerous?

The extreme criticality of Kratos stemmed from its ability to provide, even to those with less programming experience, advanced tools to evade modern corporate protection systems, including the essential multi-factor authentication.

The kit automated the creation of false login pages, structured in an extremely realistic way and often camouflaged as portals belonging to well-known productivity and design platforms, such as Microsoft, Adobe, SharePoint, OneDrive and Canva.

Through these precise imitations, the system furtively extorted credentials, passwords and valuable session cookies. According to investigations conducted by Microsoft and various data security companies, the software package in the past has operated also under alternative names such as SneakyLog or Sneaky 2FA.

Analyses also suggest that this fraudulent architecture originated from the direct evolution of previous Trojan families.

Registering a massive volume of about 15,000 phishing campaigns created monthly, it is easy to see how every single attack carried with it the destructive capacity to compromise the sensitive data of thousands of individuals simultaneously.

A network of victims across Europe and the United States

International investigations indicate that the primary targets of buyers of this extensive attack architecture resided almost exclusively in Europe and the United States.

In the United States, illicit actions heavily hit the manufacturing, retail, and healthcare sectors.

Investigators also noted a high degree of customization in the lures used; for example, the extensive use of fake U.S. W-2 tax forms, a detail that highlights the attackers’ ability to tailor assaults to maximize the number of victims.

In Europe, the attackers’ focus instead fragmented, striking a wide spectrum of organizations, including industrial facilities, affiliated law firms, technical institutes, educational institutions, and a multitude of small and medium-sized enterprises.

The definitive shutdown of the domains and the complete dismantling of Kratos’ infrastructure represent, accordingly, a formidable milestone for protecting and safeguarding the confidential information of numerous international institutions.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

Galaxy S27: the covers ‘confirm’ the new design, but not for the entire series

The first render images of Samsung Galaxy S27 Pro and Ultra, circulated in the past…

2 hours ago

The first POCO with a 10,000 mAh battery is official

Xiaomi's brand partner has officially launched in India POCO X8 Power, a mid-range smartphone that…

2 hours ago

GPT-6 Astra: OpenAI launches the new model and reopens the AGI debate

OpenAI unveiled GPT-6 Astra, the new model that the company describes as the most advanced…

2 hours ago

Amazon: the Alexa for Shopping AI can spot scam emails and SMS

Amazon has announced a new feature designed to fight scams: starting today (but only in…

4 hours ago

Midea at IFA 2026: the home becomes intelligent with SMART MASTER

Midea porta a IFA 2026 la propria visione "Simply ideal" per la casa connessa: no…

4 hours ago

Ecovacs è il brand n°1 per la robotica domestica, tutti gli annunci da IFA 2026

Ecovacs has just earned recognition as the world's No. 1 brand for home robotics in…

4 hours ago