{"id":16499,"date":"2026-07-22T23:52:21","date_gmt":"2026-07-22T23:52:21","guid":{"rendered":"https:\/\/newestek.com\/?p=16499"},"modified":"2026-07-22T23:52:21","modified_gmt":"2026-07-22T23:52:21","slug":"german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16499","title":{"rendered":"German law enforcement claims to have \u2018dismantled\u2019 mega phishing-as-a-service group Kratos"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos \u201cdeveloper and technical administrator\u201d in Indonesia.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries.<\/p>\n<p class=\"wp-block-paragraph\">Although a <a href=\"https:\/\/www.bka.de\/DE\/Presse\/Listenseite_Pressemitteilungen\/2026\/Presse2026\/260720_PM_Kratos.html\" target=\"_blank\" rel=\"noreferrer noopener\">German statement<\/a> claimed that the Kratos infrastructure \u201chas been completely disabled\u201d and that \u201cKratos-supported phishing campaigns can no longer be carried out,\u201d cybersecurity analysts and consultants question how much of a dent in enterprise phishing activity will result, and how long it will last.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA server seizure and a single arrest overseas remove infrastructure, not the intellectual property,\u201d said <a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF004767\" target=\"_blank\" rel=\"noreferrer noopener\">Frank Dickson<\/a>, group VP for security at IDC. \u201cPhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn\u2019t vanish. They just lost a vendor in a market where vendors get replaced fast.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added, \u201cseizing 200-plus servers and arresting the developer pulls a major supplier out of that specific niche. It doesn\u2019t touch the broader phishing economy. For every roach that you squish, there are a hundred that you do not see.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/noah-m-kenney-27499a166\/\" target=\"_blank\" rel=\"noreferrer noopener\">Noah Kenney<\/a>, principal consultant at Digital 520, takes an even more pessimistic view, arguing that there might not even be that much of a short-term phishing slowdown.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat makes this different from a botnet or ransomware takedown is that the people running the attacks were never part of the organization. Kratos was just a vendor,\u201d Kenney said. \u201cThe 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists. Enterprises should not read this as a drop in (likely) threat volume.\u201d<\/p>\n<p class=\"wp-block-paragraph\">One thing that the security community seems to agree on is that Kratos was a major player in the lucrative PhaaS space.\u00a0But precisely determining the percentage of PhaaS activity controlled by Kratos is impossible, given that Kratos sold their kits to others. Security researchers even disagree on what they should call Kratos kits.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMicrosoft tracks this kit as SneakyLog, others tie it to Sneaky 2FA, and KnowBe4 disputes the lineage entirely. When the security industry cannot agree on what a kit is to be called, that is because renaming and reselling is continuous rather than something that happens after a raid,\u201d Kenney said. \u201cWhat actually changed this time is the arrest and the [shutdown of the] servers. Standing up new hosting is only a weekend of work, but replacing a developer who understood how to keep an adversary in the middle proxy stable and evasive at scale is harder.\u201d<\/p>\n<p class=\"wp-block-paragraph\">IDC\u2019s Dickson added that the biggest value from the takedown is in the information gleaned from the seized servers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cKratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA, the exact technique behind a lot of the business email compromise activity of the past two years,\u201d he said. \u201cI would love to see what law enforcement does with the customer list. That, my friend, is gold.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Regardless, <a href=\"https:\/\/www.linkedin.com\/in\/assafmo\/\" target=\"_blank\" rel=\"noreferrer noopener\">Assaf Morag<\/a>, a cybersecurity researcher at Flare, dubbed the German crackdown \u201csymbolic,\u201d given Kratos\u2019 reach within phishing circles.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">He argued that the very nature of software makes it all but impossible to shut down in a meaningful way.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAlthough this is malicious infrastructure, it is still software, and modern development and deployment practices make it relatively quick to rebuild or replicate,\u201d he said. \u201cDemand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.malwarebytes.com\/blog\/authors\/metallicamvp\" target=\"_blank\" rel=\"noreferrer noopener\">Pieter Arntz<\/a>, malware intelligence researcher at Malwarebytes, agreed that the crackdown is disruptive but not definitive.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis appears to be more than a routine website seizure. The reporting points to a PhaaS platform with centralized infrastructure, subscription-style customers, and Microsoft 365 session theft \/ MFA-bypass tooling, so taking down the backend likely hurts many downstream affiliates at once. In that sense, it is a meaningful disruption to the phishing ecosystem, not just one campaign,\u201d Arntz said.<\/p>\n<p class=\"wp-block-paragraph\">But, he added, \u201ca rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations. Even if the core infrastructure is gone, the code, customer lists, and operator tradecraft can survive.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This means that customers and affiliates can shift to other phishing kits, he said, so it\u2019s likely that the takedown will create a temporary decline in Kratos-specific activity, but probably not a lasting reduction in phishing overall.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/fvillanustre\/\" target=\"_blank\" rel=\"noreferrer noopener\">Flavio Villanustre<\/a>, CISO for the LexisNexis Risk Solutions Group, also concluded that the impact of this crackdown will be short-lived.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise,\u201d he said. \u201cThese are all loosely connected individuals and akin to a lernaean hydra, with two heads growing whenever you chop off one. Their leadership emerges from their lines organically without a real center of control. This makes it almost impossible to completely eliminate these criminal organizations.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos \u201cdeveloper and technical administrator\u201d in Indonesia.\u00a0 The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries. Although a German statement claimed that the Kratos infrastructure \u201chas been completely disabled\u201d and that \u201cKratos-supported&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16499\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16499","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16499"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16499\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}