Jump to content
  • Police dismantle Kratos phishing platform, arrest developer


    Karlston

    • 92 views
    • 2 minutes
     Share


    • 92 views
    • 2 minutes

    Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.

     

    During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.

     

    The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.

     

    BKA’s announcement characterizes Kratos as “one of the world’s most widely used criminal phishing services,” with confirmed victims across 35 countries, particularly in Europe and the United States.

     

    “Authorities believe that more than 1,800 criminal customers purchased Kratos and used it to conduct roughly 15,000 phishing campaigns per month,” BKA announced.

     

    “Each campaign had the potential to affect several thousand recipients worldwide.”

     

    The phishing toolkit, which allowed threat actors to create and manage fake Microsoft authentication pages, was rented to cybercriminals for phishing attacks.

     

    The kit provided convincing login forms designed to steal email addresses and passwords, enabling the attackers to hijack Microsoft accounts.

     

    Access to these accounts was often leveraged to “commit further crimes,” states BKA, hinting at post-compromise activity such as business email compromise, data theft, account takeover, and phishing attacks targeting the victims’ contacts.

     

    The authorities estimate that the owner of the service made at least €300,000 ($342,000) since 2024, from subscription fees to the Kratos platform.

     

    With the arrest of the technical administrator and the shutdown of key parts of its infrastructure, BKA states that these phishing campaigns can no longer continue.

    Seizure banner
    Seizure banner
    Source: BKA

    A seizure banner was added to the service’s website, presenting the action as part of Operation Olympus Blade and stating that domain ownership has now been transferred to the FBI.

     

    With the servers seized, authorities can further the investigation by retrieving new forensic evidence that may lead to the identification of customers of the service.

     

    Source


    Hope you enjoyed this news post. Feedback welcome.

    Posted Wednesday 22 July 2026 at 9:20 am AEST (my time).

    News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475

    RIP Matrix


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...