A major law enforcement operation has disrupted Kratos, a sophisticated Phishing-as-a-Service PhaaSPhaaSPhaaS platform used to steal Microsoft 365365365 credentials and bypass multi-factor authentication (MFA).
However, security researchers warn that the dismantling of its central infrastructure may not end the danger, as its techniques, infrastructure patterns, and former users could fuel copycat campaigns.
Operation Olympus Blade, conducted in July 202620262026, reportedly shut down more than 200200200 servers linked to the Kratos service and led to the arrest of its alleged lead developer in Indonesia.
Before the operation, Kratos supported more than 1,8001,8001,800 criminal subscribers and was estimated to enable roughly 15,00015,00015,000 phishing campaigns each month.
Kratos gave even low-skilled cybercriminals a ready-made toolkit for launching convincing Microsoft 365365365 credential theft campaigns.
Subscribers could use phishing templates impersonating brands and services such as Adobe Creative Cloud, DocuSign, Microsoft, and invoice-sharing portals.
The platform also provided phishing domains, VPS hosting support, anti-bot controls, and campaign management through a centralized dashboard.
Kratos Kit Spurs M365 Phishing
The service was part of a broader ecosystem of adversary-in-the-middle AiTMAiTMAiTM phishing kits. Researchers found infrastructure overlaps with other phishing operations, including Tycoon, Flowerstorm, Sneaky2FA, and EvilProxy.
Such overlap means that a takedown can disrupt one operation.

At the same time, its hosting providers, affiliates, techniques, or cloned code remain available to other criminal groups.
Unlike conventional phishing pages that only collect usernames and passwords, Kratos used AiTM techniques to steal authenticated browser sessions.
The kit relayed a victim’s login attempt to the legitimate Microsoft authentication service in real time. This allowed the attackers to capture session cookies or tokens after the victim completed MFA.
A stolen token can give an attacker access to an account without repeatedly requesting a password or MFA code.
This creates a serious risk for business email compromise BECBECBEC, data theft, and long-term access to cloud services such as Outlook, Teams, SharePoint, and OneDrive.

Kratos also used several layers of evasion. Victims were often redirected from phishing emails through legitimate services, including SharePoint, OneDrive, Microsoft Forms, Canva, or Tilda.
These “buffer” pages can help malicious links avoid basic email filtering and make the final destination appear more trustworthy.
Before loading its fake login page, the kit could display Cloudflare Turnstile, reCAPTCHA, or hCaptcha challenges. These checks were designed to block automated scanners and security researchers.
The phishing pages also used geolocation checks through services such as geoplugin[.]net to filter visitors outside the attackers’ target regions.
According to ANY.RUN researchers, Kratos campaigns can be identified through distinctive assets, including barr.svg and lg.svg.
These files provide defenders with strong fingerprints for linking phishing pages to the Kratos family, even when attackers rotate domains or alter page names.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.