Kratos Phishing Kit Dismantled: What iGaming Must Know

Must read

Newsletter Signup

Sign up for all the latest news, offers and announcements.

German and US law enforcement agencies, working alongside Indonesian police, have shut down one of the most widely used phishing-as-a-service platforms ever discovered. The operation, named Kratos, ran what authorities describe as a franchise model for cybercrime – and Microsoft 365 was its primary target.

What Was Kratos?

Kratos was a phishing-as-a-service (PhaaS) kit sold to criminal customers who paid in cryptocurrency and managed their campaigns through a dedicated website and a Telegram shop. Germany’s Federal Criminal Police Office (BKA) and the Frankfurt public prosecutor’s cybercrime unit (ZIT) confirmed they took more than 200 servers offline on Monday in a coordinated operation.

An Indonesian national – named by authorities as the kit’s developer and operator – was arrested as part of the takedown. Investigators estimate roughly 1,800 paying customers, described by the BKA as franchisees, used Kratos to run approximately 15,000 phishing campaigns every month since late 2024.

How the Kit Worked

What set Kratos apart was its session cookie theft capability. Most phishing kits harvest usernames and passwords. Kratos went further: it was designed to capture the authenticated session cookie alongside credentials. That cookie is enough to walk straight past two-factor authentication and into an account as the legitimate user.

Two Attack Modes

Security researchers at ANY.RUN, who reverse-engineered the kit, found Kratos offered operators two modes. The first was a straightforward PHP credential harvester. The second – and more dangerous – was a Node.js reverse proxy that relayed the victim’s login to Microsoft in real time, capturing the resulting authenticated session. This adversary-in-the-middle (AiTM) approach is what makes standard MFA a much weaker barrier than most organisations assume.

The franchise model handled the complexity. Low-skill operators could run sophisticated AiTM campaigns with no deep technical knowledge required.

The Scale of the Operation

Since late 2024, Kratos is estimated to have reached hundreds of thousands of victims across more than 30 countries, with concentration in Europe and the United States. Investigators put the operators’ total earnings at more than 300,000 euros over that period.

Microsoft Threat Intelligence tracks the same kit under the name SneakyLog and observed it running credential and session theft against Microsoft 365 since at least early 2025. In one documented campaign on 10 February, operators sent tax-themed emails to around 100 organisations – mostly in US manufacturing, retail, and healthcare – embedding a personalised QR code in a fake W-2 document that led recipients to a spoofed Microsoft 365 login page.

The stolen data rarely stayed put. The BKA noted that compromised credentials and active sessions could be used for further phishing within a victim’s organisation, sold to other criminal actors, or converted into a foothold for business email compromise (BEC).

What This Means for iGaming

iGaming operators, affiliates, and suppliers rely heavily on Microsoft 365 for internal communications, compliance workflows, and financial operations. A tool purpose-built to bypass MFA on M365 accounts represents a direct threat to operational security, data integrity, and regulatory standing.

Credentials compromised via the Kratos phishing kit could give attackers access to internal email threads, licensing documents, financial records, or player data – any of which could trigger regulatory consequences under GDPR and sector-specific data protection frameworks. The session theft angle compounds the risk significantly: a password reset does not revoke a stolen session, which means standard incident response steps may leave attackers inside an account even after a breach is discovered.

Spotting the Signs

ANY.RUN identified a reliable detection signature in Kratos login pages: they almost always load the paired asset files barr.svg and lg.svg, then send stolen data via POST requests to endpoints such as next.php or save.php. Security teams can search historical logs for these patterns. ANY.RUN rates this pairing at 90% recall with near-zero false positives.

Microsoft is directly notifying users whose credentials or sessions were captured during known Kratos campaigns. Organisations that receive a notification should assess whether the kit’s reverse-proxy mode was involved. If it was, a password reset alone is insufficient – active sessions must also be revoked, and high-value accounts should be moved to phishing-resistant sign-in methods.

The Threat Is Not Fully Gone

The BKA confirmed that Kratos-powered campaigns cannot currently continue with the servers offline. However, the takedown did not reach the approximately 1,800 customers who already hold the kit code. ANY.RUN noted that Kratos previously operated across disposable domains, compromised WordPress sites, and infrastructure shared with other AiTM tools – the kind of setup that resurfaces under a new name once law enforcement action subsides.

The franchise model and underground demand for MFA-bypassing tools remain fully intact. This operation disrupted one platform; it did not eliminate the threat category.

Key Takeaways for iGaming Security Teams

  • Standard MFA is not sufficient protection against AiTM-based credential theft – session revocation must be part of any incident response plan.
  • Search email gateway logs and proxy logs for the Kratos detection signature: paired barr.svg and lg.svg loads followed by POSTs to next.php or save.php.
  • Phishing-resistant authentication (such as passkeys or hardware security keys) removes the session-hijacking risk that Kratos exploited.
  • The 1,800 Kratos customers still hold the kit – a resurgence under a different name is likely.

The Kratos takedown is a significant law enforcement success, but it underscores a broader truth: phishing-as-a-service has made advanced session-hijacking attacks accessible to low-skill actors at industrial scale. For iGaming businesses operating in regulated markets, where a data breach carries both reputational and licensing consequences, that is not an abstract risk – it is a live operational concern.

Stay across emerging cybersecurity threats affecting the iGaming sector by browsing the cybersecurity section on Business of iGaming, where we cover the developments that matter most to operators, suppliers, and affiliates.

Latest articles