News
MARKET SIGNAL:

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

Newsroom brief

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The Hacker News
Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Image source: The Hacker News

The Kratos phishing kit has lost its core server network, but the same customer base and code can reappear under new infrastructure.

The Hacker News reported that German and US law enforcement took down the Microsoft 365 session-theft service after investigators linked it to roughly 1,800 paying customers and about 15,000 phishing campaigns a month.

The operation gives security teams a concrete example of why ordinary multi-factor authentication is no longer enough when an attacker captures a live session token rather than only a password.

More Than 200 Servers Went Offline

The Frankfurt public prosecutor's cybercrime unit ZIT announced with Germany's Federal Criminal Police Office on Monday that more than 200 servers had been pulled offline.

Indonesian authorities arrested the man German investigators identify as the developer and operator of Kratos.

Investigators estimate that the service reached victims in the hundreds of thousands since late 2024, across more than 30 countries, with concentration in Europe and the United States.

The authorities also estimate that the operators earned more than 300,000 euros since 2024.

Kratos was sold as a phishing-as-a-service operation rather than a single campaign.

Customers paid in cryptocurrency, used a dedicated website and Telegram shop, and managed campaigns through the service.

The BKA characterised those customers as franchisees, a label that describes how a working phishing stack was packaged for lower-skill operators.

Session Cookies Made MFA Easier To Bypass

The kit's most important capability was not password theft alone.

The BKA said Kratos was designed to collect the session cookie together with the login, which can let an attacker enter an account as the user even after two-factor authentication has completed.

ANY.RUN found two operating modes after reverse-engineering the kit: a plain PHP page for credential harvesting and a Node.js reverse proxy that relayed the login to Microsoft in real time so the resulting session could be captured.

The adversary-in-the-middle structure leaves the operator with a live access channel, not merely a stolen-password database.

Microsoft 365 Accounts Need Session Checks

The BKA warned that stolen credentials could be resold, reused for further phishing or expanded through Microsoft 365 environments into business email compromise.

That path gives incident responders a different remediation sequence from an ordinary password reset.

Microsoft is notifying users caught in the campaigns.

Where Kratos only harvested credentials, password resets and MFA checks address the immediate exposure; where the reverse-proxy mode lifted an active session, the session itself has to be revoked and high-value accounts need phishing-resistant sign-in.

Defenders also have a hunting clue from the kit.

ANY.RUN found that Kratos login pages almost always loaded the paired assets barr.svg and lg.svg, then posted stolen credentials to endpoints such as next.php or save.php.

According to ANY.RUN, that pairing has 90% recall with near-zero false positives.

The server seizure stops the current Kratos infrastructure, while the public record does not identify the roughly 1,800 customers or whether replacement infrastructure is already active.

Share this article
inXf

Related articles

More
Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths
Cybersecurity

Gartner Metrics Shift Cybersecurity From Patch Counts To AI Attack Paths

Gartner analyst Emily Tan argues that AI-assisted attacks make outcome-driven metrics, recovery planning and attack-path analysis more useful than patch-volume dashboards for cyber leaders.

Minnesota Water Cyberattack Hits More Than 30 Systems
Cybersecurity

Minnesota Water Cyberattack Hits More Than 30 Systems

The Hacker News reported that Minnesota opened a statewide response after more than 30 community water systems were affected, with attribution and the access method still unconfirmed.

AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Cybersecurity

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent
Cybersecurity

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent

Cloudflare made Precursor generally available to score visitor behaviour across full browser sessions rather than one arrival check. The public record still lacks pricing, customer adoption figures and customer false-positive rates for the session-scoring product.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

Keep Reading

More Stories

Latest
Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaCloud & Data CentersAug 8, 2026Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaData Center Dynamics reported that Indosat, Ooredoo Group, Nokia and Nvidia launched Zankore by Indosat with a plan for up to 1GW of AI data centre capacity in Indonesia.Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.