Categorie: News

Authorities have killed Kratos, the PhaaS (phishing-as-a-service) kit that earned over €300,000

A major global police operation has led to the dismantling of Kratos, one of the most dangerous and widespread phishing-as-a-service platforms worldwide.

German authorities, aided by law enforcement agencies in the United States and Indonesia, have neutralized the IT infrastructure behind the malware and have arrested its alleged developer and administrator.

The operation delivers a hard blow to cybercrime, stopping a network that has proven capable of generating thousands of deceptive campaigns every month and of hitting hundreds of thousands of victims distributed across more than 30 different countries.

Farewell Kratos, the PhaaS kit has been dismantled by authorities

The Central Office for Countering Cybercrime in Frankfurt am Main (ZIT) and the Federal Criminal Police Office of Germany (BKA) led the complex investigative operation that allowed to take down more than 200 servers used by the criminals.

The success of the operation was consolidated in Indonesia through the arrest of the key technical figure behind the programming of the illegal service.

Official estimates indicate that since 2024 the Kratos kit has yielded illicit profits exceeding €300,000 to its operators, providing technological support to more than 1,800 different criminal enterprises.

Benjamin Krause, head of ZIT, emphasized that the targeted investigative approach aimed at physically disrupting illicit online platforms proves to be an extremely effective tool for ensuring greater cybersecurity on a large scale.

In line with this view, Carsten Meywirth of the BKA reiterated a strong message: those who attempt to steal online credentials cannot consider themselves safe, confirming the unwavering dedication of law enforcement in relentlessly combating these digital threats.

Why was Kratos so dangerous?

The extreme criticality of Kratos stemmed from its ability to provide, even to those with less programming experience, advanced tools to evade modern corporate protection systems, including the essential multi-factor authentication.

The kit automated the creation of false login pages, structured in an extremely realistic way and often camouflaged as portals belonging to well-known productivity and design platforms, such as Microsoft, Adobe, SharePoint, OneDrive and Canva.

Through these precise imitations, the system furtively extorted credentials, passwords and valuable session cookies. According to investigations conducted by Microsoft and various data security companies, the software package in the past has operated also under alternative names such as SneakyLog or Sneaky 2FA.

Analyses also suggest that this fraudulent architecture originated from the direct evolution of previous Trojan families.

Registering a massive volume of about 15,000 phishing campaigns created monthly, it is easy to see how every single attack carried with it the destructive capacity to compromise the sensitive data of thousands of individuals simultaneously.

A network of victims across Europe and the United States

International investigations indicate that the primary targets of buyers of this extensive attack architecture resided almost exclusively in Europe and the United States.

In the United States, illicit actions heavily hit the manufacturing, retail, and healthcare sectors.

Investigators also noted a high degree of customization in the lures used; for example, the extensive use of fake U.S. W-2 tax forms, a detail that highlights the attackers’ ability to tailor assaults to maximize the number of victims.

In Europe, the attackers’ focus instead fragmented, striking a wide spectrum of organizations, including industrial facilities, affiliated law firms, technical institutes, educational institutions, and a multitude of small and medium-sized enterprises.

The definitive shutdown of the domains and the complete dismantling of Kratos’ infrastructure represent, accordingly, a formidable milestone for protecting and safeguarding the confidential information of numerous international institutions.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

OPPO’s 10,000 mAh Giant Appears on Geekbench

The future of OPPO will be in line with that of OnePlus and Realme: according…

26 minutes ago

Xiaomi 18 Pro will also be Global, with a rear display

The next flagship series from the Chinese company should arrive fully in international markets as…

1 hour ago

Censoring sensitive information from images will be easier in Google Photos

The need to hide private details before sharing an image is an increasingly common requirement,…

1 hour ago

Roborock F25 Steam: Steam at 180°C is the star of floor cleaning

Steam becomes the real protagonist of household cleaning with Roborock F25 Steam, the new vacuum-mop…

3 hours ago

RAM prices will crash; Chinese manufacturers are preparing to flood the market

Currently the tech sector is facing a period of constant price increases, largely justified by…

3 hours ago

Warning: Instagram blocks your account if you use Meta Glasses to film covertly

Instagram has decided to intervene firmly against a worrying trend: the spread of videos filmed…

4 hours ago