By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Police Dismantle Kratos Phishing Kit Targeting Microsoft 365

German and US law enforcement agencies have dismantled the core infrastructure of the Kratos phishing kit, identified as one of the most prevalent criminal tools globally for stealing Microsoft 365 credentials. Indonesian authorities apprehended the alleged developer and operator of the kit.
In a joint announcement made on Monday, the Frankfurt Public Prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) detailed the operation. The Kratos kit is designed to mimic legitimate Microsoft 365 login pages, enabling threat actors to capture user credentials. Crucially, it is also engineered to bypass multi-factor authentication (MFA) mechanisms, a significant security layer designed to prevent unauthorized access.
The investigation, which spanned several months, involved collaboration between German federal police, the US Department of Justice, and Indonesian law enforcement. The takedown targeted servers and infrastructure used by the Kratos operation, significantly disrupting its ability to distribute the phishing kit and conduct attacks. The Frankfurt prosecutor's office stated that the kit was particularly effective due to its ability to circumvent MFA, a common defense against credential stuffing attacks.
This operation highlights the ongoing efforts by international law enforcement to combat sophisticated cybercrime tools. The Kratos kit's widespread use underscores the persistent threat posed by phishing attacks, even with the implementation of advanced security measures like MFA. The successful disruption is expected to reduce the immediate availability of this specific tool for cybercriminals targeting Microsoft 365 users.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.