Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA 32%

By Swati Khandelwal11%

7/22/2026, 5:30:00 AM

BS Summary: This article contains 16 faulty reasoning types, including Hasty Generalization, Availability Heuristic, and Negativity Bias, with Appeal to Authority as the most egregious example at 17% saturation with 109 hits. Analysis detected 700 faulty-reasoning hits from 642 analyzed words, generating a BS Score of 41.4% and a BS Rank of 32% (13,466 of 19,669 articles). This article is better (less manipulative) than 68.50% of the article peer group.

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. 
In a joint announcement on Monday, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. 
Investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month. 
Kratos harvested more than passwords. 
The kit was designed to steal the session cookie along with the login, and that cookie is enough to walk past two-factor authentication into the account as the user, the BKA said. 
ANY.RUN, which reverse-engineered the kit, found operators could pick one of two modes: a plain PHP page that only harvests credentials, or a Node.js reverse proxy designed to relay the login to Microsoft in real time and capture the resulting session. 
That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks. 
The operation ran like a franchise, with customers the BKA called franchisees. 
They paid in cryptocurrency and signed up through a dedicated website and a Telegram shop to manage their accounts and organize campaigns, so even low-skill actors could point a working AiTM kit at a target. 
The authorities put the number of victims since late 2024 in the hundreds of thousands, spread across more than 30 countries and concentrated in Europe and the United States. 
They estimate the operators earned more than 300,000 euros since 2024, and that each campaign could hit several thousand recipients. 
Kratos was already being tracked. 
Microsoft Threat Intelligence identifies the same kit as SneakyLog, a phishing-as-a-service platform it says has run credential-and-2FA theft against Microsoft 365 since at least early 2025, and it caught one campaign in the act. 
On February 10, operators sent tax-themed emails to about 100 organizations, mostly in the US, across manufacturing, retail, and healthcare, each carrying a W-2 document with a QR code personalized to the recipient that led to a fake Microsoft 365 login. 
Stolen Microsoft logins are rarely the end of the line. 
The BKA said the stolen credentials could be used for further phishing, sold to other criminals, or turned into a foothold inside companies by spreading through their Microsoft 365 environments, the familiar path from one phished inbox to business email compromise. 
Carsten Meywirth, who heads the BKA's cybercrime division, said the operation shows "that even highly professional phishing infrastructures can be effectively combated." 
The ZIT's Benjamin Krause framed it as proof of the office's "disruptive" approach of dismantling a criminal service outright rather than only charging the people behind it. 
Microsoft is notifying users caught in the campaigns. 
For anyone Microsoft is notifying, the fix depends on how they were hit. 
Where the kit only harvested credentials, a password reset and an MFA check cover it. 
Where its reverse-proxy mode lifted a live session, that session survives the reset, so it has to be revoked, with high-value accounts moved to phishing-resistant sign-in. 
Defenders hunting for exposure can look for the kit's tell: ANY.RUN found its login pages almost always load the paired assets barr.svg and lg.svg, then POST stolen credentials to endpoints like next.php or save.php. 
It rates that pairing at 90% recall with near-zero false positives. 
For now, the servers are offline and, the BKA says, Kratos-powered campaigns cannot continue. 
What the takedown did not touch is the roughly 1,800 customers or the kit code they already hold. 
ANY.RUN found Kratos running on disposable domains, compromised WordPress sites, and hosting shared with other adversary-in-the-middle kits, the kind of setup that reappears under a new name once the servers go down. 
Confirmation Bias
0%
Anchoring Bias
3.1%
Availability Heuristic
10.7%
Representativeness Heuristic
7.9%
Hindsight Bias
0%
Overconfidence Bias
5.8%
Framing Effect
8.3%
Loss Aversion
0%
Status Quo Bias
2.2%
Sunk Cost Effect
0%
Optimism Bias
6.4%
Pessimism Bias
0%
Negativity Bias
9.7%
Self-Serving Bias
4.2%
Fundamental Attribution Error
0%
Actor-Observer Bias
0%
In-Group Bias
0%
Out-Group Homogeneity Bias
0%
Halo Effect
0%
Horn Effect
0%
Dunning-Kruger Effect
0%
Recency Bias
5%
Primacy Effect
0%
Blind-Spot Bias
0%
Ad Hominem
0%
Straw Man
0%
Appeal to Authority
17%
False Dilemma
0%
Slippery Slope
5%
Circular Reasoning
0%
Hasty Generalization
14.3%
Red Herring
0%
Bandwagon
0%
Appeal to Emotion
0%
Begging the Question
0%
Post Hoc (False Cause)
2.2%
Tu Quoque
0%
Burden of Proof
0%
Appeal to Nature
0%
Composition/Division
0%
Anecdotal
0%
No True Scotsman
0%
Ambiguity (Equivocation)
2.8%
Gambler’s Fallacy
0%
Middle Ground
0%
Personal Incredulity
0%
Special Pleading
0%
Genetic Fallacy
0%
Unattributed Quote
0%
Quote-first Misdirection
0%
Biased Writer Voice
4.5%
Indoctrination
0%
Politically Left Leaning Bias
0%
Politically Right Leaning Bias
0%
Attempt to Sell a Product or Service
0%

642 words analyzed.

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.