Law enforcement agencies in Germany and the United States have dismantled the core infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform used by cybercriminals around the world, and arrested its suspected developer in Indonesia. During the coordinated operation, investigators seized more than 200 servers that supported the service, effectively taking the platform offline and disrupting its phishing operations.

 

 

The investigation was led by Frankfurt’s Central Office for Combating Internet Crime (ZIT) and Germany’s Federal Criminal Police Office (BKA), working alongside U.S. law enforcement agencies. According to the BKA, Kratos had become one of the most widely used phishing platforms available to cybercriminals, with confirmed victims identified in 35 countries, primarily across Europe and the United States.

Investigators believe the service had a large customer base. Authorities estimate that more than 1,800 criminals subscribed to Kratos and collectively launched around 15,000 phishing campaigns every month. Each campaign was capable of targeting thousands of potential victims, allowing the platform to reach a significant number of internet users worldwide.

Kratos operated under the phishing-as-a-service model, allowing customers to rent ready-made phishing tools instead of developing their own. The platform specialized in creating fraudulent Microsoft authentication pages that closely resembled legitimate login portals. Victims who entered their credentials into these fake pages unknowingly provided attackers with access to their Microsoft accounts.

According to investigators, stolen Microsoft credentials were frequently used in follow-up attacks. Access to compromised accounts could enable cybercriminals to conduct business email compromise (BEC) schemes, steal sensitive corporate or personal information, impersonate victims in additional phishing campaigns, or take over email accounts to expand their attacks to new targets.

Authorities estimate that the operator earned at least €300,000 (approximately $342,000) in subscription revenue since 2024 by renting access to the platform. The investigation suggests the service functioned as a commercial criminal operation, with customers paying recurring fees in exchange for phishing infrastructure, management tools, and technical support.

The suspected technical administrator was arrested in Indonesia as part of the international operation. German authorities believe removing the individual responsible for maintaining the platform, together with the seizure of its infrastructure, has brought Kratos’ phishing activities to an end.

Visitors attempting to access the platform’s website are now presented with a seizure notice stating that the action was carried out as part of Operation Olympus Blade. The notice also confirms that control of the domain has been transferred to the U.S. Federal Bureau of Investigation (FBI).

With more than 200 servers now in the hands of investigators, law enforcement agencies expect to recover additional forensic evidence from the seized infrastructure. Authorities hope the collected data will help identify other individuals who purchased access to Kratos, participated in phishing campaigns, or otherwise supported the platform’s criminal operations. The investigation remains ongoing, and additional enforcement actions may follow as the evidence is analyzed.

Leave a Reply