CTIPilot
← Back to Daily brief 2026-07-24
NOTABLENATOA1threat

German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns

A German-led takedown removes Kratos's infrastructure, but the AiTM tradecraft and affiliate base survive, as Tycoon2FA already showed

Analysis

Germany's Bundeskriminalamt (BKA), with the Frankfurt cybercrime prosecutor (ZIT), US law enforcement and Indonesian authorities, announced on 20 July 2026 the takedown of Kratos, a phishing-as-a-service (PhaaS) platform that sold subscribers a turnkey adversary-in-the-middle toolkit for generating convincing Microsoft 365 authentication pages (BKA, 2026-07-20). Per BKA and Trend Micro (which had tracked Sneaky2FA's evolution into Kratos since December 2024) the platform added browser-in-the-browser (BitB) fake login windows in November 2025 and Cloudflare Turnstile anti-bot challenges to blunt automated analysis and takedown, and ran an estimated 15,000 phishing campaigns a month across 200+ servers for roughly 1,800 subscribers (Trend Micro, 2026-07-22). Authorities seized the infrastructure and arrested the platform's developer/technical administrator in Indonesia (BKA, 2026-07-20).

Cited evidence

Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.

Trend Micro Research 2026-07-22

bedeutender Ermittlungserfolg gegen eine der weltweit gefährlichsten Phishing-as-a-Service-Gruppierung

Bundeskriminalamt (BKA)

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.