Germany says Kratos phishing service infrastructure has been taken down
German, US and Indonesian authorities disrupted Kratos, a phishing kit tied to more than 200 servers and 15,000 campaigns a month.
By Dominic Okoye · Staff Writer
· 3 min read
German authorities said they dismantled the core infrastructure behind Kratos, a phishing-as-a-service kit that allegedly generated more than €300,000, about $342,000, since 2024. The operation, supported by US and Indonesian authorities, also led to the arrest in Indonesia of the person accused of being the kit’s developer and technical administrator.
The Frankfurt am Main Central Office for Combating Internet Crime, known as ZIT, and Germany’s Federal Criminal Police Office, the BKA, described Kratos as one of the most common and dangerous phishing kits available to criminals. They said the service enabled lower-skill operators to steal passwords and session cookies, including in attacks designed to get around multifactor authentication.
For the security industry, the case is another example of law enforcement targeting the commercial infrastructure behind cybercrime rather than only the people running individual campaigns. Authorities said more than 200 servers were taken offline or otherwise rendered unusable. The BKA did not describe the technical or legal steps used to do that.
Kratos was sold as a shortcut for credential theft
According to ZIT and the BKA, Kratos gave customers convincing Microsoft-themed login pages that could be used to collect credentials. The agencies said phishing pages created with the kit were used against hundreds of thousands of victims in more than 30 countries.
German authorities estimated that more than 1,800 criminal enterprises used Kratos. They also said the kit was linked to about 15,000 phishing campaigns each month, with each campaign capable of reaching several thousand recipients worldwide.
The announcement did not say whether law enforcement is seeking additional suspects beyond the person arrested in Indonesia. It also did not disclose whether authorities seized customer records, payment data or administration panels that could identify operators who bought access to the service.
ZIT head Benjamin Krause said the case showed the value of “disruptive law enforcement,” in which investigators seek to dismantle criminal services while also identifying and prosecuting suspects. Carsten Meywirth, head of the BKA’s cybercrime department, said the action against Kratos showed that professional phishing infrastructure can be countered.
Security vendors have tracked overlapping names
German authorities referred to the service as Kratos. Public reporting from security researchers has connected Kratos to names including SneakyLog and Sneaky 2FA, though the lineage is not cleanly settled across vendors.
Microsoft has said Kratos was also known as SneakyLog and reported earlier this year that SneakyLog was used in campaigns aimed at US citizens with fake W-2 tax form lures. Microsoft placed SneakyLog’s entry into the phishing kit market in early 2025.
KnowBe4, in a February investigation, described Kratos differently, saying it appeared to have evolved from a prior family of commercial trojans and infostealers. The company did not identify SneakyLog or Sneaky 2FA as earlier names for Kratos, and it said the first signs of Kratos appeared in January 2026. That timeline sits awkwardly beside the German authorities’ statement that the Kratos operation earned money since 2024.
Researchers have also reported a wider set of lures than the Microsoft authentication pages named by German authorities. Heal Security reported on July 16 that Kratos offered themes tied to SharePoint, OneDrive, Microsoft Forms, Canva and Tilda. KnowBe4 also identified Adobe-themed lures.
Open source reporting has generally placed most targets in the US and Europe. Microsoft identified manufacturing, retail and healthcare as key US sectors targeted by SneakyLog campaigns. ANY.RUN has reported European targeting across industrial companies, law firms, polytechnic institutions, schools, small and midsize businesses and other organizations.
This story draws on original reporting from The Register.