News
MARKET SIGNAL:

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

Newsroom brief

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Image source: The Hacker News

The Kratos phishing kit has lost its core server network, but the same customer base and code can reappear under new infrastructure.

The Hacker News reported that German and US law enforcement took down the Microsoft 365 session-theft service after investigators linked it to roughly 1,800 paying customers and about 15,000 phishing campaigns a month.

The operation gives security teams a concrete example of why ordinary multi-factor authentication is no longer enough when an attacker captures a live session token rather than only a password.

More Than 200 Servers Went Offline

The Frankfurt public prosecutor's cybercrime unit ZIT announced with Germany's Federal Criminal Police Office on Monday that more than 200 servers had been pulled offline.

Indonesian authorities arrested the man German investigators identify as the developer and operator of Kratos.

Investigators estimate that the service reached victims in the hundreds of thousands since late 2024, across more than 30 countries, with concentration in Europe and the United States.

The authorities also estimate that the operators earned more than 300,000 euros since 2024.

Kratos was sold as a phishing-as-a-service operation rather than a single campaign.

Customers paid in cryptocurrency, used a dedicated website and Telegram shop, and managed campaigns through the service.

The BKA characterised those customers as franchisees, a label that describes how a working phishing stack was packaged for lower-skill operators.

Session Cookies Made MFA Easier To Bypass

The kit's most important capability was not password theft alone.

The BKA said Kratos was designed to collect the session cookie together with the login, which can let an attacker enter an account as the user even after two-factor authentication has completed.

ANY.RUN found two operating modes after reverse-engineering the kit: a plain PHP page for credential harvesting and a Node.js reverse proxy that relayed the login to Microsoft in real time so the resulting session could be captured.

The adversary-in-the-middle structure leaves the operator with a live access channel, not merely a stolen-password database.

Microsoft 365 Accounts Need Session Checks

The BKA warned that stolen credentials could be resold, reused for further phishing or expanded through Microsoft 365 environments into business email compromise.

That path gives incident responders a different remediation sequence from an ordinary password reset.

Microsoft is notifying users caught in the campaigns.

Where Kratos only harvested credentials, password resets and MFA checks address the immediate exposure; where the reverse-proxy mode lifted an active session, the session itself has to be revoked and high-value accounts need phishing-resistant sign-in.

Defenders also have a hunting clue from the kit.

ANY.RUN found that Kratos login pages almost always loaded the paired assets barr.svg and lg.svg, then posted stolen credentials to endpoints such as next.php or save.php.

According to ANY.RUN, that pairing has 90% recall with near-zero false positives.

The server seizure stops the current Kratos infrastructure, while the public record does not identify the roughly 1,800 customers or whether replacement infrastructure is already active.

Share this article
inXf

Related articles

More
AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Cybersecurity

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent
Cybersecurity

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent

Cloudflare made Precursor generally available to score visitor behaviour across full browser sessions rather than one arrival check. The public record still lacks pricing, customer adoption figures and customer false-positive rates for the session-scoring product.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk
Cybersecurity

Injective SDK npm Compromise Exposes Wallet-Key Theft Risk

Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Socket said the malicious release was downloaded 310 times before deprecation, while Ox Security counted 87 direct dependencies and described a six-figure cumulative download count across dependent packages.

Keep Reading

More Stories

Latest
OpenAI Presence Makes Enterprise AI Agents A Consulting SaleAIJul 22, 2026OpenAI Presence Makes Enterprise AI Agents A Consulting SaleOpenAI’s Presence service is available to eligible enterprise customers through deployed engineers, not as a self-service product, with pricing still scoped individually.Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsFintech & Digital PaymentsJul 22, 2026Augustus Raises $180m For Dollar Rails Across Emerging-Market FintechsAugustus announced a $180 million Series B at a $1 billion valuation, with funding aimed at dollar accounts, payment rails and stablecoin-enabled banking for fintechs and banks across Latin America, Southeast Asia, the Middle East and Africa.China IPv6 Plan Advances Single-Stack Network And Metadata ControlsTelco & ConnectivityJul 22, 2026China IPv6 Plan Advances Single-Stack Network And Metadata ControlsChina is setting 2027 and 2030 IPv6 targets while pushing IPv6+ work that could give carriers more metadata about traffic, raising policy questions for network and cloud buyers outside China.Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresCloud & Data CentersJul 22, 2026Prysmian Signs $6.29bn Molex Cable Deal For AI Data CentresData Center Dynamics reported that Prysmian’s €5.5 billion Molex agreement includes a €550 million upfront payment and a capacity plan to more than double US fibre output.Spain AI Campus Seeks 300 MW With On-Site Power PlanCloud & Data CentersJul 22, 2026Spain AI Campus Seeks 300 MW With On-Site Power PlanData Center Knowledge reported that EdgeMode, BlackBerry AIF and Mora are seeking regional support for DC MALPICA, a proposed €3 billion ($3.4 billion), 300 MW AI campus whose power model remains partly undisclosed.e& UAE And Core42 Launch Sovereign AI Compute PlatformCloud & Data CentersJul 21, 2026e& UAE And Core42 Launch Sovereign AI Compute PlatformMiddle East AI News reported that e& UAE and Core42 launched Sovereign AI Compute, giving UAE enterprises and government bodies in-country GPU access with data residency, connectivity and vendor-claimed zero egress fees.AI Coding Agents Face Sandbox-Escape Findings Across Four ToolsCybersecurityJul 21, 2026AI Coding Agents Face Sandbox-Escape Findings Across Four ToolsBleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeChips & SemiconductorsJul 21, 2026Microsoft Adds AMD Helios AI Racks To Azure Without Order SizeMicrosoft will deploy AMD Helios rack-scale AI accelerators for Azure AI workloads, with watts, dollars and rack counts still absent from the public terms of the commitment.AliExpress Hit With Record €550m EU Fine Over Illegal GoodsCapital & PolicyJul 21, 2026AliExpress Hit With Record €550m EU Fine Over Illegal GoodsBBC reported that the European Commission imposed a record €550m Digital Services Act penalty on AliExpress and ordered the Alibaba-owned marketplace to file a corrective action plan by 20 October.Neo Raises $100M To Control Enterprise AI Software ActionsCybersecurityJul 21, 2026Neo Raises $100M To Control Enterprise AI Software ActionsSecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.Z.ai Tests Gigawatt AI Data Centre Built On Domestic ChipsCloud & Data CentersJul 21, 2026Z.ai Tests Gigawatt AI Data Centre Built On Domestic ChipsUnite.AI reported that Z.ai has begun operating part of a gigawatt-class AI data centre built on Chinese-made chips, highlighting how export controls are pushing large-scale model training toward domestic compute stacks.Digital Takumi AWS Route 53 Outage Exposes Root-Account Recovery RiskCloud & Data CentersJul 21, 2026Digital Takumi AWS Route 53 Outage Exposes Root-Account Recovery RiskThe Register links a suspended AWS Route 53 account to Digital Takumi-managed websites and connected Google Workspace email going offline after billing warnings, MFA recovery and DNS hosting sat inside one operating loop.