ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

German and U.S. authorities dismantle Kratos phishing kit, arrest developer in Indonesia

German and U.S. authorities have taken down the core infrastructure of Kratos, a phishing-as-a-service platform, and arrested its alleged developer and technical administrator in Indonesia. Frankfurt’s Central Office for Combating Internet Crime and Germany’s Federal Criminal Police, known as the BKA, led the operation with support from U.S. law enforcement, seizing more than 200 servers and taking the platform offline.


The BKA described Kratos as among the most widely used and dangerous phishing kits in circulation, with victims confirmed in more than 30 countries, concentrated in Europe and the United States. Authorities said more than 1,800 criminal customers had purchased access to the kit and used it to run an estimated 15,000 phishing campaigns each month, with each campaign capable of reaching several thousand recipients worldwide. The operation behind Kratos is believed to have earned more than €300,000, or roughly $342,000, since 2024 through subscription fees.


Kratos gave low-skill criminals the tools to build convincing, Microsoft-themed login pages designed to harvest usernames, passwords and session cookies, allowing attackers to bypass multi-factor authentication and take over victims’ accounts. The BKA said compromised accounts were often used to carry out further crimes. Authorities did not disclose how the more than 200 servers were neutralized, though the BKA noted that past takedowns of similar services have relied on legal warrants served to hosting providers and cooperation with internet service providers to null-route or sinkhole traffic linked to suspect IP addresses.


A seizure banner has been placed on the service’s website identifying the action as Operation Olympus Blade and stating that ownership of the domain has been transferred to the FBI. The BKA said the seized servers will allow investigators to gather further forensic evidence that could help identify Kratos’s customers. The announcement did not indicate whether additional suspects are being pursued beyond the individual arrested in Indonesia.


Dr. Benjamin Krause, head of the Frankfurt prosecutor’s office cybercrime unit, said the approach of disruptive law enforcement works, noting that in addition to identifying and prosecuting suspects, authorities again succeeded in dismantling a criminal online service. Carsten Meywirth, head of the BKA’s cybercrime department, said anyone stealing login credentials through fake websites should not feel safe, calling the action against Kratos evidence that even highly professional phishing infrastructure can be effectively dismantled and describing it as a clear signal that phishing will be consistently pursued by the BKA.


German authorities referred to the platform only as Kratos, though outside security researchers have linked it to earlier products marketed under the names SneakyLog and Sneaky 2FA. Accounts of the kit’s history and origins vary among researchers. Microsoft has said Kratos was also known as SneakyLog and believes that service entered the phishing kit market in early 2025, while KnowBe4 has said the first signs of Kratos itself did not appear until January 2026 and that the kit evolved out of an earlier line of commercial trojans and infostealers rather than from SneakyLog or Sneaky 2FA. German authorities cited fake Microsoft authentication pages as the platform’s phishing lures, while outside researchers have reported a broader range of templates. Security firm Heal Security reported as recently as July 16 that Kratos offered lures themed around SharePoint, OneDrive, Microsoft Forms, Canva and Tilda, among other services, and KnowBe4 said its own investigation in February found Adobe-themed lures as well.


Researchers largely agree that Kratos customers targeted victims primarily in the United States and Europe. Microsoft identified manufacturing, retail and health care as the main targeted industries in the U.S., while ANY.RUN reported that targets in Europe included industrial organizations, law firms, polytechnic institutions, schools and small and midsize businesses, among others.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543