Police Dismantle Kratos Phishing Kit Used to Bypass Microsoft 365 MFA

German and United States law enforcement agencies have seized the core infrastructure behind Kratos, a phishing-as-a-service kit that German investigators describe as one of the most widely used criminal phishing platforms in the world. The takedown, announced jointly by the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA), targeted a tool built specifically to steal Microsoft 365 login sessions and circumvent multi-factor authentication.

Separately, Indonesian authorities arrested a man they allege developed and operated the Kratos kit, marking a rare instance of a phishing-kit author being identified and detained rather than the operation merely being disrupted at the infrastructure level.

Kits like Kratos work by intercepting session data during a real-time phishing attack, allowing an attacker to hijack an already-authenticated session and sidestep MFA protections entirely rather than trying to guess or steal a one-time code. Because Microsoft 365 is used by a large share of businesses and government agencies worldwide, phishing kits purpose-built to target it have become an attractive commodity sold to lower-skilled criminals on underground forums.

The action fits a broader pattern of international police operations aimed at the phishing-as-a-service ecosystem, which has lowered the technical bar for account-takeover fraud and business email compromise. Reporting on the takedown is based on the joint ZIT/BKA statement as covered by The Hacker News; full details of the case, including the number of victims affected, had not been disclosed at the time of reporting.

Read the original report →