What happened
German federal authorities and US law enforcement jointly dismantled the infrastructure behind Kratos, a phishing-as-a-service platform capable of hijacking Microsoft 365 sessions and circumventing multi-factor authentication. Indonesian police separately arrested the individual believed to have created and operated the kit. In a parallel development, LG Electronics announced it will remove any smart TV applications on its webOS platform that covertly enroll users' televisions as residential proxy nodes — a decision prompted by research showing that over 42 percent of apps in the webOS store were quietly routing third-party internet traffic through consumers' home networks.
Why it matters for your business
Kratos represented a sophisticated threat because it could defeat MFA protections that many organizations treat as a security ceiling rather than a single layer — its takedown is a reminder that session-hijacking attacks can render standard authentication controls insufficient on their own. Security teams should audit Microsoft 365 conditional access policies and consider token-binding or phishing-resistant FIDO2 authentication as next-layer defenses. The LG proxy story is equally instructive for operations leaders: devices on corporate or guest Wi-Fi networks — including employee smart TVs in conference rooms or executive suites — may be silently funneling outside traffic, creating liability and network integrity risks that most asset inventories never capture.
What to watch next
Investigators have not confirmed whether Kratos source code or customer lists remain in circulation, meaning copycat or successor kits could emerge quickly, and enterprises should monitor threat intelligence feeds for related indicators of compromise. On the smart TV front, regulators in the EU and US have been scrutinizing app-store accountability for connected devices, so LG's move may pressure other manufacturers — Samsung, Roku, and Amazon among them — to conduct similar audits of their own platforms.
