● News

Kratos Phishing Platform Dismantled as Developer Arrested in International Operation

July 24, 2026 · snewle
Kratos Phishing Platform Dismantled as Developer Arrested in International Operation

German and U.S. law enforcement authorities have successfully shut down the infrastructure of the Kratos phishing platform, which was used to steal Microsoft 365 accounts and bypass multi-factor authentication. The operation resulted in the seizure of over 200 servers, while the suspected developer and administrator of the service was arrested in Indonesia.

The takedown operation, named Olympus Blade, was coordinated by the Central Office for Combating Cybercrime of the Frankfurt Public Prosecutor’s Office (ZIT) and the Federal Criminal Police Office of Germany (BKA), with participation from American law enforcement agencies.

How Did the Kratos Platform Operate?

BKA describes the Kratos phishing platform as one of the most popular phishing services in the criminal underground. According to investigators, the platform served more than 1,800 clients who conducted approximately 15,000 phishing campaigns per month. Each of these campaigns could reach several thousand recipients, and the creators of Kratos earned at least 300,000 euros from their operation.

Since late 2024, hundreds of thousands of users in more than 30 countries worldwide fell victim to these attacks, with confirmed victims primarily located in Europe and the United States. Kratos operated under a PhaaS (phishing-as-a-service) model, where clients paid for access using cryptocurrency and could manage their accounts through a dedicated website or Telegram bot to create fake Microsoft authorization pages.

What Made Kratos Particularly Dangerous?

According to analysts from ANY.RUN, the platform supported two operational modes. The first used a standard PHP page that collected victims’ usernames and passwords. The second employed a Node.js reverse proxy and enabled adversary-in-the-middle attacks, where Kratos transmitted Microsoft account credentials to hackers in real-time and intercepted the session created after login.

This approach allowed attackers to obtain not only login credentials but also session cookies. Using these cookies, criminals could access victim accounts even when two-factor authentication was enabled. Microsoft had been tracking this service under the name SneakyLog since early 2025.

What Happens Next in the Investigation?

BKA representatives emphasize that phishing campaigns will not be able to continue following the server shutdown and the arrest of the service administrator. Forensic experts are currently examining the confiscated servers, and authorities expect that data found on them will help identify the service’s clients.

Source: Xakep