- 974
- 263
Law enforcement agencies in Germany and the United States have shut down the infrastructure of the Kratos phishing platform, which was used to steal Microsoft 365 accounts and bypass multi-factor authentication. Authorities seized over 200 servers, and the service's alleged developer and administrator were arrested in Indonesia.
The operation to shut down the platform, dubbed Olympus Blade, was coordinated by the Central Cybercrime Office of the Frankfurt Public Prosecutor's Office (ZIT) and the German Federal Criminal Police Office (BKA), with the participation of American law enforcement.
The BKA describes Kratos as one of the most popular phishing services among criminals. Investigators estimate that over 1,800 clients used the platform, conducting approximately 15,000 phishing campaigns per month. Each of these mailings could reach several thousand recipients, and the creators of Kratos earned at least €300,000 from them.
According to law enforcement, hundreds of thousands of users in more than 30 countries have fallen victim to such attacks since the end of 2024 (confirmed victims are primarily located in Europe and the United States).
Kratos operated on a PhaaS (phishing-as-a-service) model. Clients paid for access with cryptocurrency, after which they could manage their accounts through a separate website or a Telegram bot and create fake Microsoft login pages.
As recently reported by ANY.RUN analysts, the platform supported two modes. The first used a regular PHP page that collected victims' logins and passwords. The second was a Node.js reverse proxy that enabled adversary-in-the-middle attacks: in this case, Kratos transmitted Microsoft account credentials to hackers in real time and intercepted the session created after login. As a result, the attackers obtained not only the login and password but also the session cookie. It could be used to log into victims' accounts, even if they had two-factor authentication enabled. Microsoft researchers had been monitoring this service, dubbed SneakyLog, since early 2025. As BKA representatives now emphasize, the phishing campaigns will no longer be possible after the Kratos servers are shut down and the service administrator is arrested. Forensic experts are currently examining the confiscated servers, and the data found on them is expected to help identify the service's clients. @ xakep.ru

The operation to shut down the platform, dubbed Olympus Blade, was coordinated by the Central Cybercrime Office of the Frankfurt Public Prosecutor's Office (ZIT) and the German Federal Criminal Police Office (BKA), with the participation of American law enforcement.
The BKA describes Kratos as one of the most popular phishing services among criminals. Investigators estimate that over 1,800 clients used the platform, conducting approximately 15,000 phishing campaigns per month. Each of these mailings could reach several thousand recipients, and the creators of Kratos earned at least €300,000 from them.
According to law enforcement, hundreds of thousands of users in more than 30 countries have fallen victim to such attacks since the end of 2024 (confirmed victims are primarily located in Europe and the United States).
Kratos operated on a PhaaS (phishing-as-a-service) model. Clients paid for access with cryptocurrency, after which they could manage their accounts through a separate website or a Telegram bot and create fake Microsoft login pages.
As recently reported by ANY.RUN analysts, the platform supported two modes. The first used a regular PHP page that collected victims' logins and passwords. The second was a Node.js reverse proxy that enabled adversary-in-the-middle attacks: in this case, Kratos transmitted Microsoft account credentials to hackers in real time and intercepted the session created after login. As a result, the attackers obtained not only the login and password but also the session cookie. It could be used to log into victims' accounts, even if they had two-factor authentication enabled. Microsoft researchers had been monitoring this service, dubbed SneakyLog, since early 2025. As BKA representatives now emphasize, the phishing campaigns will no longer be possible after the Kratos servers are shut down and the service administrator is arrested. Forensic experts are currently examining the confiscated servers, and the data found on them is expected to help identify the service's clients. @ xakep.ru
