A major global police operation has led to the dismantling of Kratos, one of the most dangerous and widespread phishing-as-a-service platforms worldwide.
German authorities, aided by law enforcement agencies in the United States and Indonesia, have neutralized the IT infrastructure behind the malware and have arrested its alleged developer and administrator.
The operation delivers a hard blow to cybercrime, stopping a network that has proven capable of generating thousands of deceptive campaigns every month and of hitting hundreds of thousands of victims distributed across more than 30 different countries.
The Central Office for Countering Cybercrime in Frankfurt am Main (ZIT) and the Federal Criminal Police Office of Germany (BKA) led the complex investigative operation that allowed to take down more than 200 servers used by the criminals.
The success of the operation was consolidated in Indonesia through the arrest of the key technical figure behind the programming of the illegal service.
Official estimates indicate that since 2024 the Kratos kit has yielded illicit profits exceeding €300,000 to its operators, providing technological support to more than 1,800 different criminal enterprises.
Benjamin Krause, head of ZIT, emphasized that the targeted investigative approach aimed at physically disrupting illicit online platforms proves to be an extremely effective tool for ensuring greater cybersecurity on a large scale.
In line with this view, Carsten Meywirth of the BKA reiterated a strong message: those who attempt to steal online credentials cannot consider themselves safe, confirming the unwavering dedication of law enforcement in relentlessly combating these digital threats.
The extreme criticality of Kratos stemmed from its ability to provide, even to those with less programming experience, advanced tools to evade modern corporate protection systems, including the essential multi-factor authentication.
The kit automated the creation of false login pages, structured in an extremely realistic way and often camouflaged as portals belonging to well-known productivity and design platforms, such as Microsoft, Adobe, SharePoint, OneDrive and Canva.
Through these precise imitations, the system furtively extorted credentials, passwords and valuable session cookies. According to investigations conducted by Microsoft and various data security companies, the software package in the past has operated also under alternative names such as SneakyLog or Sneaky 2FA.
Analyses also suggest that this fraudulent architecture originated from the direct evolution of previous Trojan families.
Registering a massive volume of about 15,000 phishing campaigns created monthly, it is easy to see how every single attack carried with it the destructive capacity to compromise the sensitive data of thousands of individuals simultaneously.
International investigations indicate that the primary targets of buyers of this extensive attack architecture resided almost exclusively in Europe and the United States.
In the United States, illicit actions heavily hit the manufacturing, retail, and healthcare sectors.
Investigators also noted a high degree of customization in the lures used; for example, the extensive use of fake U.S. W-2 tax forms, a detail that highlights the attackers’ ability to tailor assaults to maximize the number of victims.
In Europe, the attackers’ focus instead fragmented, striking a wide spectrum of organizations, including industrial facilities, affiliated law firms, technical institutes, educational institutions, and a multitude of small and medium-sized enterprises.
The definitive shutdown of the domains and the complete dismantling of Kratos’ infrastructure represent, accordingly, a formidable milestone for protecting and safeguarding the confidential information of numerous international institutions.
The future of OPPO will be in line with that of OnePlus and Realme: according…
The next flagship series from the Chinese company should arrive fully in international markets as…
The need to hide private details before sharing an image is an increasingly common requirement,…
Steam becomes the real protagonist of household cleaning with Roborock F25 Steam, the new vacuum-mop…
Currently the tech sector is facing a period of constant price increases, largely justified by…
Instagram has decided to intervene firmly against a worrying trend: the spread of videos filmed…