Threat Brief — 2026-07-22 — PhaaS Takedown and Proxy Crackdown
Executive summary: Law enforcement dismantled Kratos, a global phishing-as-a-service platform, arresting its developer in Indonesia — a significant disruption to the criminal phishing supply chain. LG moved to block residential proxy abuse through Smart TV apps, responding to research showing TVs being co-opted as always-on proxy nodes. A new analysis challenges the prevailing narrative that AI is driving ransomware's acceleration, instead attributing it to ecosystem fragmentation and new entrants targeting under-defended organisations.
Top items
- Kratos PhaaS infrastructure seized, developer arrested in Indonesia. German and U.S. authorities coordinated the takedown of Kratos, a phishing-as-a-service platform with global reach, arresting its developer in Indonesia. This removes a key enabler from the criminal phishing ecosystem and follows a pattern of recent PhaaS disruptions. (src: BleepingComputer)
- LG to suspend Smart TV apps that create residential proxy nodes. LG Electronics USA announced it will ban apps that turn Smart TVs into always-on residential proxy exit nodes, following researcher disclosures that such apps were being deployed at scale. This is a defensive supply-chain move that could pressure other consumer IoT vendors to follow suit. (src: KrebsOnSecurity)
- Ransomware acceleration driven by ecosystem fragmentation, not AI. DarkReading analysis attributes rising ransomware activity to the splintering of established groups, emergence of new attackers, and expansion into less-defended sectors rather than AI-enabled tooling. This is relevant to risk modelling — defenders should weight attacker proliferation and target diversification over speculative AI-enhanced capability. (src: DarkReading)
Themes
Law enforcement momentum against PhaaS. The Kratos takedown continues a trend of coordinated cross-border action against phishing infrastructure, potentially squeezing mid-tier operators who relied on rented platforms rather than building their own kits.
Residential proxy abuse hits mainstream vendor response. LG's policy shift signals that the residential-proxy-as-monetised-IoT problem has crossed from researcher concern into vendor accountability — relevant for any organisation tracking egress traffic from consumer devices on corporate or home networks.
