German and US law enforcement dismantled Kratos, a phishing kit ranked among the world's most prevalent tools for credential theft. Indonesian authorities arrested the developer and operator behind the infrastructure.

The Frankfurt public prosecutor's cybercrime unit and Germany's Federal Criminal Police Office led the takedown in coordination with US partners. Investigators characterized Kratos as exceptionally dangerous because it specifically targets Microsoft 365 sessions and bypasses multi-factor authentication. The kit automates phishing attacks at scale, allowing criminals with minimal technical expertise to launch convincing credential-harvesting campaigns against enterprise users.

Kratos operated by hosting malicious login pages that mimic legitimate Microsoft authentication interfaces. When targets entered credentials, the kit captured them in real time. The system then automated MFA bypass by intercepting one-time codes during the authentication process, granting attackers immediate access to compromised Microsoft 365 accounts. This two-stage compromise eliminated the protection that MFA typically provides against credential theft alone.

The infrastructure supported thousands of simultaneous phishing campaigns. Operators rented access to the kit, with pricing tiers enabling criminals from different skill levels to conduct attacks. This commoditization of phishing explains why Kratos achieved such widespread adoption in underground criminal forums.

Law enforcement seized core servers and shut down command-and-control infrastructure. The arrest of the primary developer removes a critical node from the criminal supply chain, though related individuals may continue operating variants. Investigators recovered logs documenting victim targeting patterns and geographic distribution of attacks.

Organizations relying on Microsoft 365 faced direct risk from Kratos campaigns. The kit's effectiveness against standard MFA created a protection gap for users who believed MFA alone secured their accounts. Phishing-resistant authentication methods, such as passwordless sign-in or hardware security keys, would have stopped Kratos attacks completely. Standard TOTP or SMS-based MFA proved insufficient because