Global Phishing-as-a-Service Platform 'Kratos' Dismantled, Developer Arrested
International law enforcement, led by German and U.S. authorities, has successfully dismantled **Kratos**, a prominent phishing-as-a-service (PhaaS) platform. The operation resulted in the arrest of the platform's developer in Indonesia and the seizure of over 200 servers, effectively disrupting a global network of cybercriminals.

Authorities in Germany and the U.S. have announced the successful disruption of **Kratos**, a significant phishing-as-a-service (PhaaS) platform that facilitated cyberattacks across 35 countries. The operation culminated in the arrest of the platform's developer in Indonesia and the seizure of more than 200 servers, rendering the malicious service inoperable.
### International Collaboration Leads to Takedown
The coordinated effort was spearheaded by Frankfurtβs Prosecutor General Office (ZIT) and Germanyβs Federal Police (**BKA**), working in close collaboration with U.S. law enforcement agencies. This international cooperation underscores the global nature of cybercrime and the necessity for cross-border enforcement.
### Kratos: A Global Threat
The **BKA** characterized **Kratos** as "one of the worldβs most widely used criminal phishing services." Investigations revealed that over 1,800 criminal customers had purchased access to **Kratos**, leveraging it to launch approximately 15,000 phishing campaigns per month. Each campaign had the potential to impact thousands of recipients worldwide, primarily targeting users in Europe and the United States.
### The Mechanics of Kratos
The **Kratos** toolkit enabled threat actors to create and manage highly convincing fake **Microsoft** authentication pages. These sophisticated login forms were designed to steal email addresses and passwords, allowing attackers to hijack **Microsoft** accounts. Compromised accounts were often used for further criminal activities, including business email compromise (BEC), data theft, account takeover, and subsequent phishing attacks targeting the victims' contacts.
### Financial Impact and Future Investigations
Authorities estimate that the owner of the **Kratos** service generated at least β¬300,000 ($342,000) since 2024 through subscription fees. With the arrest of the technical administrator and the shutdown of its core infrastructure, the **BKA** asserts that these phishing campaigns can no longer continue.

**Seizure banner**
*Source: BKA*
A seizure banner has been placed on the service's website, identifying the action as part of "Operation Olympus Blade" and confirming that domain ownership has been transferred to the **FBI**. The seized servers are expected to yield crucial forensic evidence, which may lead to the identification and prosecution of the platform's criminal customers.