German authorities, working with the United States and Indonesia, dismantled the core infrastructure of Kratos, a phishing-as-a-service platform described as one of the world’s most widely used criminal phishing services. Investigators seized or neutralized more than 200 servers and arrested the alleged developer and technical administrator in Indonesia, a move authorities said rendered the service inoperable. The action was carried out under Operation Olympus Blade, and the FBI took control of Kratos-linked domains to support follow-on investigation and customer identification.
Kratos supplied Microsoft-themed phishing pages designed to steal credentials and session cookies, allowing attackers to hijack accounts and bypass multi-factor authentication. Authorities said the platform was used by roughly 1,800 criminal customers to launch about 15,000 phishing campaigns per month against victims in at least 35 countries, with organizations in the United States and Europe—particularly in manufacturing, retail, healthcare, and education—among the main targets. Investigators estimate the operation generated more than €300,000 since 2024.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro said its TrendAI team began providing threat intelligence and infrastructure analysis to Germany's BKA in 2025 to support the investigation into the Kratos phishing-as-a-service platform. The assistance helped inform the later Operation Olympus Blade disruption.
Authorities arrested the alleged developer and technical administrator of Kratos in Indonesia as part of the takedown. Investigators linked the platform to roughly 1,800 criminal customers running about 15,000 phishing campaigns per month.
German and U.S. authorities, with support from Indonesia, dismantled the core infrastructure behind the Kratos phishing-as-a-service platform. The operation included seizing or neutralizing more than 200 servers, and authorities said the action rendered the service inoperable.
As part of Operation Olympus Blade, the FBI took control of Kratos domains to support the ongoing investigation and help identify the platform's customers. This detail was reported alongside the broader law enforcement disruption of the service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcetrendmicro.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcebka.de
Open sourceany.run
Open sourcebka.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.