In a significant crackdown, authorities in Germany and the United States have dismantled the core infrastructure of Kratos, a notorious phishing-as-a-service (PhaaS) platform, while also arresting its developer in Indonesia.
During this operation, law enforcement seized over 200 servers, disrupting the platform’s malicious services and rendering them inoperable.
The action was spearheaded by Frankfurt’s Prosecutor General’s Office (ZIT) and the German Federal Police (BKA), in collaboration with American law enforcement agencies.
The BKA described Kratos as “one of the most extensively used criminal phishing services globally,” with victims spanning 35 countries, particularly in Europe and the United States.
“Authorities estimate that over 1,800 criminal customers purchased Kratos, engaging in approximately 15,000 phishing campaigns each month,” announced the BKA.
“Each campaign had the potential to impact thousands of recipients worldwide.”
This sophisticated phishing toolkit enabled attackers to create and manage counterfeit Microsoft authentication pages, which were rented out to facilitate phishing attacks.
The toolkit provided a convincing login form designed to capture email addresses and passwords, allowing attackers to hijack Microsoft accounts.
Once accessed, these accounts were often exploited to “commit further crimes,” as noted by the BKA, including business email compromises, data theft, and phishing targeting contacts of the victims.
Authorities believe the service’s owner has accrued at least 300,000 euros ($342,000) in subscription fees from the Kratos platform since 2024.
With the arrest of its technical administrators and the shutdown of crucial infrastructure components, the BKA asserts that these phishing operations can no longer be conducted.

Source: BKA
A seizure banner has been added to the service’s website as part of Operation Olympus Blade, announcing the transfer of domain ownership to the FBI.
The seizure of these servers will assist authorities in advancing their investigation, providing new forensic evidence that may help identify the service’s customers.
Security teams document only 54% of successful attacks, issuing warnings for just 14%. The remainder often goes undetected.
Picus’ whitepaper illustrates how to test SIEM and EDR rules through breach and attack simulations, ensuring threats do not escape notice.
Source: www.bleepingcomputer.com




