2 min read

Kratos phishing platform dismantled, developer arrested

Authorities seized more than 200 Kratos servers and arrested its developer, disrupting a phishing service used in 35 countries.

Image: BleepingComputer

Authorities in Germany and the United States have dismantled the central infrastructure of Kratos, a phishing-as-a-service platform used worldwide. The operation seized more than 200 servers, rendering the service inoperable, while Indonesian authorities arrested its developer.

The action was led by Frankfurt’s Prosecutor General Office (ZIT) and Germany’s Federal Criminal Police Office (BKA), in cooperation with U.S. law enforcement agencies.

Kratos phishing service targeted Microsoft accounts

The BKA described Kratos as “one of the world’s most widely used criminal phishing services.” Authorities confirmed victims in 35 countries, particularly across Europe and the United States.

Recommended reading

OpenAI models escaped a sandbox and breached Hugging Face

“Authorities believe that more than 1,800 criminal customers purchased Kratos and used it to conduct roughly 15,000 phishing campaigns per month. Each campaign had the potential to affect several thousand recipients worldwide.”

Germany’s Federal Criminal Police Office

Kratos was rented to cybercriminals who used it to create and manage fake Microsoft authentication pages. Its phishing kits included convincing login forms designed to steal email addresses and passwords, allowing attackers to hijack Microsoft accounts.

The compromised accounts were then used to commit further crimes, including business email compromise, data theft, account takeover, and attacks against the victims' contacts, according to the BKA.

Kratos infrastructure seized in Operation Olympus Blade

Authorities estimate that the service’s owner earned at least €300,000 ($342,000) from subscription fees since 2024. The arrest of its technical administrator and the seizure of key infrastructure have stopped the platform’s phishing campaigns, the BKA said.

Seizure banner — Source: BKA

A seizure banner on Kratos' website says the action was part of Operation Olympus Blade and that domain ownership has been transferred to the FBI. Investigators can now examine the seized servers for forensic evidence that could help identify the platform’s customers.

Article image
Article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

/ Keep reading