German and U.S. law enforcement agencies have dismantled the core infrastructure of Kratos, one of the world’s largest phishing-as-a-service (PhaaS) platforms, in a coordinated international operation that also led to the arrest of its alleged developer in Indonesia.

The operation, led by Germany’s Frankfurt Prosecutor General’s Office (ZIT) and the Federal Criminal Police Office (BKA) in cooperation with U.S. authorities, resulted in the seizure of more than 200 servers, effectively disabling the cybercrime platform and preventing it from continuing its phishing operations.

According to the BKA, Kratos was one of the most widely used phishing services globally, with confirmed victims in 35 countries, particularly across Europe and the United States. Investigators believe more than 1,800 cybercriminals subscribed to the platform and used it to launch approximately 15,000 phishing campaigns every month, with each campaign capable of targeting thousands of potential victims.

Kratos operated as a subscription-based phishing toolkit that enabled attackers to create realistic Microsoft login pages designed to steal usernames, email addresses, and passwords. Once victims entered their credentials, attackers could hijack Microsoft accounts and use them for additional criminal activities, including business email compromise (BEC), account takeovers, data theft, and further phishing attacks targeting the victim’s contacts.

Authorities estimate the platform generated at least €300,000 (around $342,000) in subscription revenue since 2024. With the arrest of the platform’s technical administrator and the seizure of its infrastructure, investigators believe the service can no longer operate.

READ
Public WordPress 'wp2shell' Exploits Released, Millions of Sites Urged to Patch Immediately

Visitors attempting to access the Kratos website are now greeted with a law enforcement seizure notice stating that the action was carried out as part of Operation Olympus Blade. The notice also confirms that ownership of the platform’s domains has been transferred to the FBI.

Investigators will now analyze data recovered from the seized servers to identify additional suspects, including customers who purchased and used the phishing service. Authorities expect the digital evidence to help uncover more cybercriminals involved in phishing campaigns worldwide and support future international investigations into organized cybercrime.


Buy ExpressVPN with PayPal or Credit Card

Advertisement