Skip to content

German Authorities Dismantle Phishing-as-a-Service Group Kratos

Bottom line: The dismantling of Kratos disrupts a PhaaS operation but is likely to reduce phishing activity only temporarily, as the customer base and competing products remain intact.

German law enforcement authorities have seized the infrastructure of the phishing-as-a-service group Kratos in an international operation and arrested a technical administrator in Indonesia. However, security experts warn that this represents only a temporary disruption in a burgeoning PhaaS market.

Authorities from Germany, the United States, Indonesia and other countries were involved in the action against Kratos. German authorities stated that the Kratos infrastructure has been “completely deactivated” and phishing campaigns supported by Kratos “can no longer be carried out”. The operation resulted in the seizure of over 200 servers and ended with the arrest of an unnamed Kratos developer and technical administrator.

Frank Dickson of IDC, however, points to the structural weaknesses of such operations: while the seizure of infrastructure and a single arrest removes the technology, it does not remove the knowledge behind it. Kratos had approximately 1,800 customers. This customer base has not disappeared, but has merely lost a provider in a market where replacements are quickly available. PhaaS kits are routinely cloned, modified and resold. Dickson compares this to pest control: “For every pest you kill, there are a hundred you don’t see.”

Noah Kenney of Digital 520 sees even less impact. Unlike the dismantling of botnets or ransomware operations, the attackers were never part of Kratos itself – Kratos was merely a provider. The 1,800 customers still have their target lists, distribution infrastructure and already established access. The tools are offline, but the actors remain active and are looking for replacement solutions that already exist.

Additional complexity arises from nomenclature: different security firms refer to Kratos kits differently (Microsoft calls it “SneakyLog”, others “Sneaky 2FA”). This disagreement results from continuous renaming and resale – not from rare events like raids. Kratos specialized in “Adversary-in-the-Middle” attacks and generated convincingly authentic Microsoft 365 login pages that harvest session tokens and bypass multi-factor authentication. This technique was central to many business email compromise attacks over the past two years.

Security researchers describe the operation as “symbolic”. The software-based nature of the infrastructure enables rapid rebuild and replication processes – modern development and deployment require only days to a few weeks for this. Demand will likely shift to competing providers and the ecosystem can recover. The greatest value for authorities lies in the information obtained from the seized servers – particularly the customer lists could prove valuable for further investigations.


Source: www.csoonline.com · Published July 23, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: