The German Bundeskriminalamt (BKA), the Zentrale Stelle zur Aufklärung von Internetkriminalität (ZIT), and U.S. authorities have dismantled the infrastructure behind Kratos, one of the world's most prevalent phishing kits, seizing more than 200 servers and arresting the platform's developer in Indonesia. The operation, dubbed "Olympus Blade" by the Federal Bureau of Investigation, struck a service that German investigators estimate had roughly 1,800 paying customers and generated over €300,000 in revenue since 2024. The date is July 20, 2026, but the significance lies in the method: Kratos was not a specialist's technical tool, but a criminal franchise that democratized adversary-in-the-middle attacks against Microsoft 365 accounts.
- Germany, the United States, and Indonesia conducted a joint operation against the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting the developer.
- Kratos operated on two technical tiers: static credential harvesting via PHP and a Node.js reverse proxy for real-time interception of Microsoft 365 sessions, bypassing traditional MFA.
- Microsoft Threat Intelligence tracks the same kit under the name "SneakyLog," active since at least early 2025, with a documented tax-themed campaign on February 10, 2026, targeting roughly 100 U.S. organizations.
- The takedown did not touch the roughly 1,800 franchisee customers or the kit code in their possession, leaving the threat ecosystem intact.
The Franchise Model: How Kratos Industrialized AiTM Phishing
BKA investigations reconstructed an operational model that German investigators explicitly defined as a "franchisee" structure: customers purchased access to the service via a website and a Telegram shop channel, paying in cryptocurrencies. They were not sophisticated technical actors, but low-skill users who bought the ability to run advanced phishing campaigns. According to German authorities' estimates, these roughly 1,800 customers managed approximately 15,000 phishing campaigns per month.
The kit featured two distinct modes, both analyzed by ANY.RUN during reverse-engineering. The first was a static PHP credential harvester that captured usernames and passwords on spoofed login pages. The second, technically more sophisticated, implemented a Node.js reverse proxy designed to forward authentication requests to Microsoft in real time and intercept the resulting session, including MFA tokens. This adversary-in-the-middle mechanism renders traditional multi-factor authentication based on SMS, TOTP, or push notifications ineffective.
Technical signatures identified by ANY.RUN include paired SVG assets (barr.svg and lg.svg) and specific POST endpoints (next.php and save.php). The detection rate with these indicators stands at 90% recall with near-zero false positives, according to the analysis.
The Threat Map: From SneakyLog to the 2026 Tax Campaigns
Microsoft Threat Intelligence attributed the alternate name "SneakyLog" to Kratos, documenting its activity since at least early 2025. The convergence between ANY.RUN's analysis and Microsoft's tracking linked the kit to concrete campaigns with precise operational details. A tax-themed campaign is documented for February 10, 2026, using emails containing W-2 documents and custom QR codes, directed at roughly 100 U.S. organizations across manufacturing, retail, healthcare, and education sectors.
Documented victims from the operation number in the hundreds of thousands since late 2024, distributed across more than 30 countries with concentrations in Europe and the United States. Operators used disposable domains, compromised WordPress sites, and shared hosting that also housed other AiTM kits. Stolen credentials and sessions were used for further phishing, sale on underground markets, or propagation of Business Email Compromise through Microsoft 365 environments.
"that even highly professional phishing infrastructures can be effectively combated" — Carsten Meywirth, head of the BKA's cybercrime division
Operation Olympus Blade: Law Enforcement Tactics and Limits
The FBI posted seizure banners on domains associated with the operation, publicly identified as "Olympus Blade." The developer arrested in Indonesia is described by BleepingComputer as a "technical administrator"; his name has not been made public in any of the sources consulted. German authorities estimated revenue exceeding €300,000 since 2024; BleepingComputer converts the figure to $342,000 USD.
An alternative figure emerges from GBHackers, which reports 850 victims across 35 countries. The discrepancy with BKA estimates (hundreds of thousands of victims across more than 30 countries) likely reflects different metrics: the former may refer to specifically documented incidents, while the latter represents an aggregated estimate of the potential or actual victim pool. The dossier does not clarify which interpretation is correct.
What the operation did not hit is equally significant. The roughly 1,800 franchisee customers were not arrested nor apparently publicly identified. The kit code remains in their possession. The source does not specify whether authorities possess recoverable data from the seized servers that could lead to further arrests, nor whether the customers are under investigation.
Immediate Actions
- Audit active sessions on corporate Microsoft 365 accounts: victims of the reverse-proxy mode require explicit session revocation, not just a password reset.
- Migrate high-value accounts to phishing-resistant MFA (FIDO2/passkeys): authentication based on SMS, TOTP, or push notifications does not stop AiTM.
- Hunt network logs for indicators associated with Kratos/SneakyLog: SVG assets barr.svg and lg.svg, POST endpoints next.php and save.php, noting the 90% recall documented by ANY.RUN.
- Differentiate response by attack mode: password reset is sufficient for victims of the PHP harvester alone; session revocation is mandatory for reverse-proxy victims.
Why Infrastructure Takedown Does Not End the Game
The editorial reading urges caution on the operational significance of this operation. The developer's arrest and server seizure interrupt the flow of updates and technical support, but do not directly deter demand. The 1,800 customers have already acquired the minimal technical skills sufficient to replicate or migrate to competing kits. The phishing-as-a-service ecosystem is structured to absorb these disruptions: operators regroup, code gets recycled, domains regenerate.
The strategic value of the operation lies rather in demonstrating that criminal infrastructures can be mapped with sufficient precision for coordinated transnational action. The technical component — ANY.RUN's analysis, Microsoft's tracking, the convergence of investigative sources — was as decisive as the judicial action. Without this foundation, Olympus Blade would have been impossible.
The problem of defensive resilience remains open: organizations that do not migrate to phishing-resistant MFA remain exposed despite this operation, because the AiTM technique is replicable by any subsequent kit.
Information has been verified against cited sources and is current as of publication.
Sources
- https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
- https://gbhackers.com/police-dismantle-kratos-phishing-as-a-service-platform/
- https://www.bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer/
- https://www.scworld.com/brief/german-authorities-dismantle-kratos-phishing-as-a-service-infrastructure
- https://www.scworld.com/brief/celine-dion-concert-comeback-sparks-ticket-scam-warning
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability