Authorities Dismantle Kratos Phishing-as-a-Service Platform and Seize 200 Servers

German and US law enforcement agencies have taken down the central infrastructure of Kratos, one of the world’s most widespread criminal phishing-as-a-service (PhaaS) platforms, in a coordinated operation dubbed “Operation Olympus Blade”.

The Frankfurt am Main Public Prosecutor’s Office Central Office for Combating Internet Crime (ZIT) and Germany’s Federal Criminal Police Office (BKA) partnered with US authorities, including the FBI’s Dallas Field Office and the US Attorney’s Office for the Northern District of Texas, to dismantle Kratos.

The developer and technical administrator of the platform was arrested in Indonesia by local authorities, marking a significant international law enforcement collaboration.

Kratos Phishing-as-a-Service Platform Dismantled

As part of the action, investigators rendered more than 200 servers of the Kratos infrastructure inoperable and seized the group’s domain under a US federal seizure warrant issued by the Northern District of Texas.

Kratos functioned as a digital toolkit used primarily to build and manage deceptively realistic fake Microsoft authentication pages designed to harvest victims’ login credentials, including passwords and email addresses.

Critically, the kit was engineered to also steal session cookies, allowing attackers to bypass two-factor authentication entirely once credentials were captured.

Stolen data was reportedly repurposed for further phishing attacks, resale to third parties, or lateral infiltration of corporate networks through widely deployed Microsoft enterprise solutions.

Kratos operated on a phishing-as-a-service business model, leasing its toolkit to other cybercriminals who then executed the actual campaigns, lowering the technical barrier for less-skilled threat actors.

Distribution ran through a dedicated website and a Telegram shop where customers could register, manage accounts, and pay in cryptocurrency.

Since 2024, the group is estimated to have generated over €300,000 in revenue, with more than 1,800 criminal “franchisees” purchasing access and collectively running approximately 15,000 phishing campaigns per month, each capable of targeting thousands of recipients.

Authorities identified roughly 850 confirmed victims across 35 countries, primarily in Europe and the United States, though officials noted the broader victim count since late 2024 likely runs into the hundreds of thousands globally given the campaign volume. Microsoft is directly notifying affected users of the phishing exposure.

BKA Cybercrime Division head Carsten Meywirth stated that the operation proves even highly professional phishing infrastructures can be effectively dismantled, calling it a clear warning to other cyber actors.

ZIT chief Dr. Benjamin Krause added that the “disruptive prosecution” approach succeeded not only in identifying and prosecuting suspects but in shutting down the criminal service entirely.

German investigators are pursuing charges under Section 127 of the German Criminal Code (StGB) for commercially operating a criminal trading platform, Section 269 StGB for aggravated forgery of legally significant data, and Section 263a StGB for preparing computer fraud.

With the administrator in custody and core technical components offline, Kratos-supported phishing campaigns can no longer be conducted, effectively ending the platform’s operations. Germany’s Federal Office for Information Security (BSI) has published phishing prevention guidance for potentially affected users.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories