Actor Profile
The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform. Active since late 2024, the operator ran a franchise-style criminal service with approximately 1,800 paying customers ("franchisees") who conducted roughly 15,000 phishing campaigns monthly. The operation generated over 300,000 euros through cryptocurrency payments, offering low-skill actors turnkey adversary-in-the-middle (AiTM) capabilities via a dedicated website and Telegram shop. The operator's motivation was financial, providing a commercialized phishing infrastructure that enabled credential and session theft targeting Microsoft 365 accounts across more than 30 countries, with concentration in Europe and the United States.
TTPs (Tactics, Techniques, Procedures)
Kratos employed adversary-in-the-middle (AiTM) techniques to bypass multi-factor authentication by stealing live session cookies alongside credentials. The kit offered two operational modes: a basic PHP credential harvester and a sophisticated Node.js reverse proxy that relayed authentication requests to Microsoft in real time to capture valid session tokens (T1539: Steal Web Session Cookie, T1566.002: Phishing - Spearphishing Link). Initial access vectors included tax-themed spearphishing emails with QR code-embedded documents leading to fake Microsoft 365 login pages (T1598.003: Phishing for Information - Spearphishing Link). Stolen credentials enabled lateral movement through Microsoft 365 environments (T1078: Valid Accounts) and facilitated business email compromise. The infrastructure leveraged disposable domains, compromised WordPress sites, and shared hosting to evade detection. Technical indicators include paired SVG assets (barr.svg, lg.svg) and POST endpoints (next.php, save.php).
Targets & Patterns
Kratos targeted Microsoft 365 users across multiple sectors including manufacturing, retail, and healthcare, with victims spanning more than 30 countries. Geographic concentration focused on Europe and the United States, with one documented campaign on February 10, 2025, hitting approximately 100 US organizations. Authorities estimate hundreds of thousands of victims since late 2024. The targeting pattern reflects opportunistic, broad-spectrum phishing enabled by the PhaaS model, where 1,800 customers could independently select targets. The focus on Microsoft 365 accounts indicates strategic interest in cloud-based enterprise environments that provide pathways to business email compromise, credential resale, and further phishing operations. The franchise structure democratized sophisticated AiTM attacks, enabling low-skill actors to execute campaigns against high-value corporate targets previously requiring advanced technical capabilities.
Historical Context
Microsoft Threat Intelligence previously tracked Kratos under the designation SneakyLog, identifying it as a phishing-as-a-service platform active since at least early 2025. The February 10, 2025 campaign documented by Microsoft involved tax-themed lures with personalized QR codes targeting US organizations. The joint German-US-Indonesian law enforcement operation in July 2026 dismantled over 200 servers, marking a significant disruption to one of the world's most widely used criminal phishing kits. However, the approximately 1,800 customers and existing kit code remain unaddressed, and ANY.RUN analysis suggests the infrastructure pattern—disposable domains, compromised WordPress sites, shared hosting with other AiTM kits—is designed for resilience and likely to reemerge under new branding. The operation represents an evolution in PhaaS maturity, offering turnkey AiTM capabilities through user-friendly interfaces that previously required specialized technical knowledge.
Defensive Recommendations
- Revoke active Microsoft 365 sessions for compromised accounts, as password resets alone do not invalidate stolen session cookies captured via AiTM techniques (T1539)
- Deploy phishing-resistant authentication methods such as FIDO2/WebAuthn hardware tokens or certificate-based authentication to mitigate adversary-in-the-middle session theft
- Hunt for Kratos indicators by scanning web traffic logs for paired assets barr.svg and lg.svg loading patterns, and POST requests to endpoints matching next.php or save.php (90% detection rate per ANY.RUN analysis)
- Monitor for anomalous Microsoft 365 sign-in activity including impossible travel, unfamiliar devices, or session token reuse patterns using Azure AD Identity Protection and Conditional Access policies
- Implement email security controls to detect and block QR code-based phishing lures, particularly tax-themed or document-based social engineering targeting corporate users (T1566.002)
---
# Geopolitical Context
Geopolitical Context
The coordinated takedown of Kratos represents a significant trilateral law enforcement operation targeting cybercrime-as-a-service infrastructure that enabled credential theft and session hijacking at scale. The operation demonstrates growing transatlantic cooperation on cybercrime enforcement, with German and US authorities dismantling server infrastructure while Indonesian police arrested the alleged developer. The platform's business model—offering adversary-in-the-middle capabilities to approximately 1,800 paying customers who conducted roughly 15,000 phishing campaigns monthly—illustrates the maturation of the cybercrime economy into franchise-like service offerings accessible to low-skill actors. With hundreds of thousands of victims concentrated in Europe and the United States since late 2024, the campaign targeted the Microsoft 365 ecosystem specifically, exploiting the gap between legacy multi-factor authentication and phishing-resistant authentication methods. The operation aligns with Germany's stated "disruptive" approach to cybercrime enforcement, prioritizing infrastructure dismantlement over prosecution alone.
State Actor Alignment
This appears to be a purely criminal operation with no evident state sponsorship or strategic intelligence objectives. The cryptocurrency-based payment model, Telegram-based customer management, and profit motive (estimated at over 300,000 euros since 2024) are consistent with organized cybercrime rather than state-directed activity. The arrest of an Indonesian national as the alleged developer, combined with the platform's availability to any paying customer across more than 30 countries, suggests a decentralized criminal marketplace rather than state-aligned infrastructure. The targeting pattern—opportunistic phishing across multiple sectors including manufacturing, retail, and healthcare—lacks the focus typically associated with state-sponsored operations. No sanctions designations or state attribution have been announced in connection with this takedown.
Business Impacty pro region
The concentration of victims in Europe and the United States reflects both the geographic focus of Kratos customers and the prevalence of Microsoft 365 adoption in Western economies. The platform's capability to bypass standard MFA through session cookie theft poses particular risk to European organizations, where GDPR compliance requirements make credential compromise incidents costly and legally consequential. The involvement of Indonesian authorities in arresting the alleged operator demonstrates Southeast Asian engagement in transnational cybercrime enforcement, though the region remains a source jurisdiction for cybercrime infrastructure and talent. The takedown of over 200 servers disrupts immediate campaign capability but leaves approximately 1,800 customers and their copies of the kit code intact, suggesting the threat will likely reconstitute under different branding. For European defenders, the operation underscores the inadequacy of legacy MFA against adversary-in-the-middle techniques and the need for phishing-resistant authentication standards such as FIDO2 or certificate-based methods.
Forecast
If the approximately 1,800 former Kratos customers retain copies of the kit code, similar phishing-as-a-service platforms are likely to emerge within weeks to months, potentially under different branding but employing comparable adversary-in-the-middle techniques. If law enforcement pursues the customer base identified through the seized infrastructure, secondary arrests and disruptions may follow in jurisdictions with active cybercrime prosecution capacity. If Microsoft's victim notification and remediation guidance is implemented broadly, organizations that experienced session theft but only reset passwords without revoking active sessions will remain compromised until those sessions expire or are manually terminated. If the operation's "disruptive" model proves effective in measurably reducing phishing campaign volume, other European jurisdictions may adopt similar infrastructure-focused takedown strategies against cybercrime-as-a-service platforms. If the kit's technical signatures (barr.svg, lg.svg, next.php, save.php endpoints) are widely adopted by defenders, detection rates for reconstituted campaigns may improve in the near term, though operators will likely modify these indicators in subsequent versions.
